Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jh6x-6qvc-pcgv

Опубликовано: 11 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can cause limited impact to confidentiality of the application.

SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can cause limited impact to confidentiality of the application.

EPSS

Процентиль: 45%
0.00227
Низкий

5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5
nvd
больше 1 года назад

SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can cause limited impact to confidentiality of the application.

EPSS

Процентиль: 45%
0.00227
Низкий

5 Medium

CVSS3

Дефекты

CWE-79