Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr29-vx49-cpq4

Опубликовано: 08 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.

Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.

EPSS

Процентиль: 43%
0.00208
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.2
nvd
10 месяцев назад

Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.

CVSS3: 4.2
fstec
10 месяцев назад

Уязвимость платформы электронной коммерции SAP Commerce Cloud, связанная с недостатками процедуры авторизации, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации

EPSS

Процентиль: 43%
0.00208
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-862