Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27680

Опубликовано: 14 мая 2026
Источник: nvd
CVSS3: 3.1
CVSS3: 4.3
EPSS Низкий

Описание

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:netweaver_application_server_abap:758:*:*:*:sap_ui:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:816:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00173
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 3.1
github
4 месяца назад

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, while integrity and availability are not impacted.

EPSS

Процентиль: 7%
0.00173
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-276