Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4g5-mcc7-3767

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.

EPSS

Процентиль: 39%
0.00178
Низкий

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 5.4
nvd
около 5 лет назад

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.

EPSS

Процентиль: 39%
0.00178
Низкий

Дефекты

CWE-444