LabKey Server Community Edition before 18.3.0-61806.763 contains a reflected cross-site scripting vulnerability via the onerror parameter in the /__r2/query endpoints, which allows an unauthenticated remote attacker to inject arbitrary JavaScript.
View the template here CVE-2019-3911.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2019-3911