ETQ Reliance CG是美国ETQ公司的一款质量管理系统。 ETQ Reliance CG存在安全漏洞,该漏洞源于SQLConverterServlet组件容易受到反射型跨站脚本攻击,可能导致在用户环境中执行未授权脚本。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| ETQ | Reliance CG (legacy) | < SE.2025.1 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| ETQ | Reliance CG (legacy) | 0 ~ SE.2025.1 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the SQLConverterServlet component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user's context. The affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version SE.2025.1. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34141.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2025-34140 | 8.7 HIGH | ETQ Reliance 安全漏洞 |
| CVE-2025-34143 | ETQ Reliance CG 安全漏洞 | |
| CVE-2025-34142 | ETQ Reliance CG 代码问题漏洞 |
暂无评论