Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24325

Опубликовано: 10 фев. 2026
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:businessobjects_enterprise:430:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_enterprise:2025:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_enterprise:2027:*:*:*:*:*:*:*

EPSS

Процентиль: 8%
0.00185
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
github
5 месяцев назад

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.

EPSS

Процентиль: 8%
0.00185
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79