AvantFAX 3.3.3 contains a cross-site scripting vulnerability via an arbitrary parameter name submitted to the default URL, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
id: CVE-2017-18024
info:
name: AvantFAX 3.3.3 - Cross-Site Scripting
author: pikpikcu
severit
...