Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wqv-v86p-8q8g

Опубликовано: 14 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.

EPSS

Процентиль: 7%
0.00173
Низкий

3.1 Low

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 3.1
nvd
4 месяца назад

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.

EPSS

Процентиль: 7%
0.00173
Низкий

3.1 Low

CVSS3

Дефекты

CWE-276