CVE-2025-34141: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in ETQ Reliance CG (legacy)
A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverterServlet` component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user's context. The affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version SE.2025.1.
AI Analysis
Technical Summary
This vulnerability involves improper neutralization of input during web page generation (CWE-79), leading to reflected XSS in the SQLConverterServlet of ETQ Reliance CG (legacy). An attacker can craft a malicious URL that, when clicked by an authenticated user, causes execution of unauthorized scripts in the user's browser context. The servlet was unnecessarily exposed, increasing the attack surface. The vendor has disabled the vulnerable servlet in version SE.2025.1, effectively mitigating the issue in that release. No direct patch or fix is linked for earlier versions, and no cloud service remediation applies.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary scripts in the context of an authenticated user's browser session, potentially leading to session hijacking, unauthorized actions, or information disclosure within the affected application. However, exploitation requires user interaction and authentication. There are no known exploits in the wild at this time.
Mitigation Recommendations
The vulnerability has been mitigated by disabling the vulnerable SQLConverterServlet in ETQ Reliance CG version SE.2025.1. Users of earlier versions should upgrade to this or a later version where the servlet is disabled. Since no official patch links are provided, upgrading or disabling the affected component manually is recommended. Monitor vendor advisories for any future patches or guidance.
CVE-2025-34141: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in ETQ Reliance CG (legacy)
Description
A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverterServlet` component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user's context. The affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version SE.2025.1.
CVSS v4.0
Score 5.1medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper neutralization of input during web page generation (CWE-79), leading to reflected XSS in the SQLConverterServlet of ETQ Reliance CG (legacy). An attacker can craft a malicious URL that, when clicked by an authenticated user, causes execution of unauthorized scripts in the user's browser context. The servlet was unnecessarily exposed, increasing the attack surface. The vendor has disabled the vulnerable servlet in version SE.2025.1, effectively mitigating the issue in that release. No direct patch or fix is linked for earlier versions, and no cloud service remediation applies.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary scripts in the context of an authenticated user's browser session, potentially leading to session hijacking, unauthorized actions, or information disclosure within the affected application. However, exploitation requires user interaction and authentication. There are no known exploits in the wild at this time.
Mitigation Recommendations
The vulnerability has been mitigated by disabling the vulnerable SQLConverterServlet in ETQ Reliance CG version SE.2025.1. Users of earlier versions should upgrade to this or a later version where the servlet is disabled. Since no official patch links are provided, upgrading or disabling the affected component manually is recommended. Monitor vendor advisories for any future patches or guidance.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T19:15:22.563Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687f881fa83201eaac1c0ebe
Added to database: 07/22/2025, 12:46:23 UTC
Last enriched: 05/16/2026, 09:17:05 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 174
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.