Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mh58-mm5c-49p8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.

EPSS

Процентиль: 44%
0.00221
Низкий

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.8
nvd
больше 6 лет назад

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.

EPSS

Процентиль: 44%
0.00221
Низкий

Дефекты

CWE-94