Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmf8-wm54-9xq4

Опубликовано: 14 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.

EPSS

Процентиль: 43%
0.00209
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 5.4
nvd
почти 3 года назад

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.

EPSS

Процентиль: 43%
0.00209
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-434