AvantFAX 3.3.3 contains a cross-site scripting vulnerability via an arbitrary parameter name submitted to the default URL, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
View the template here CVE-2017-18024.yaml
References:
http://packetstormsecurity.com/files/145776/AvantFAX-3.3.3-Cross-Site-Scripting.html