Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5ph-qv4m-hcxv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.

SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.

EPSS

Процентиль: 38%
0.00162
Низкий

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.

EPSS

Процентиль: 38%
0.00162
Низкий