Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxvr-26hw-h83x

Опубликовано: 14 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.

SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.

EPSS

Процентиль: 23%
0.00076
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 4.8
nvd
около 1 года назад

SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.

CVSS3: 4.8
fstec
около 1 года назад

Уязвимость программных интеграционных платформ SAP NetWeaver AS Java, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить межсайтовый скриптинг

EPSS

Процентиль: 23%
0.00076
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-434