Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m53r-gw8p-792j

Опубликовано: 13 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application.

SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application.

EPSS

Процентиль: 59%
0.0038
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application.

CVSS3: 5.4
fstec
почти 2 года назад

Уязвимость компонента URL Handler программного обеспечения интерактивного обучения пользователей SAP-систем SAP Companion, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 59%
0.0038
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79