Apak Wholesale Floorplanning Finance and allows XSS via the mainForm:loanNotesnotes:0:rich_text_editor_note_text parameter to WFS/agreementView.faces in the Notes section. Although versions and are confirmed to be affected, all versions with the vulnerable WYSIWYG ?Notes? section are likely affected.

Source: CVE-2019-17551

