Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22v9-2p6r-qwwx

Опубликовано: 11 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.

EPSS

Процентиль: 24%
0.00079
Низкий

8.8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.8
nvd
6 месяцев назад

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.

CVSS3: 8.8
fstec
6 месяцев назад

Уязвимость интерактивной консоли Swagger UI платформы электронной коммерции SAP Commerce, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 24%
0.00079
Низкий

8.8 High

CVSS3

Дефекты

CWE-79