CVE-2025-34141 MEDIUM

CVE-2025-34141: ETQ Reliance CG < SE.2025.1 Reflected XSS in `SQLConverterServlet`

Vendor Etq
Product Reliance CG (legacy)
Weakness CWE-79 · XSS
Published July 22, 2025
Last update May 15, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverterServlet` component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user's context. The affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version SE.2025.1.

Key dates

02Disclosure timeline

July 22, 2025 CVE published
May 15, 2026 Record updated