Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-31328

Опубликовано: 22 апр. 2025
Источник: nvd
CVSS3: 4.6
EPSS Низкий

Описание

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.

EPSS

Процентиль: 6%
0.00025
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.6
github
10 месяцев назад

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.

CVSS3: 4.6
fstec
10 месяцев назад

Уязвимость функции OData программной платформы SAP S/4HANA, позволяющая нарушителю оказывать влияние на целостность и конфиденциальность защищаемой информации

EPSS

Процентиль: 6%
0.00025
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-352