Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-42478

Опубликовано: 12 дек. 2023
Источник: nvd
CVSS3: 7.5
CVSS3: 7.6
EPSS Низкий

Описание

SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_objects_business_intelligence_platform:430:*:*:*:*:*:*:*

EPSS

Процентиль: 17%
0.00052
Низкий

7.5 High

CVSS3

7.6 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.5
github
около 2 лет назад

SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.

EPSS

Процентиль: 17%
0.00052
Низкий

7.5 High

CVSS3

7.6 High

CVSS3

Дефекты

CWE-79