Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xg4v-qw5v-j6h2

Опубликовано: 11 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

EPSS

Процентиль: 62%
0.00424
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-80

Связанные уязвимости

CVSS3: 3.7
nvd
почти 3 года назад

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

EPSS

Процентиль: 62%
0.00424
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-80