Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmwc-hm8x-6w23

Опубликовано: 13 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.

EPSS

Процентиль: 24%
0.0008
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
23 дня назад

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.

CVSS3: 6.1
fstec
24 дня назад

Уязвимость программной интеграционной платформы SAP NetWeaver Enterprise Portal, связанная с недостаточной защитой структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 24%
0.0008
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79