Логотип exploitDog
bind:CVE-2025-26659
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-26659

Количество 3

Количество 3

nvd логотип

CVE-2025-26659

11 месяцев назад

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript payload executes in the scope of victim�s browser potentially compromising their data and/or manipulating browser content. This leads to a limited impact on confidentiality and integrity. There is no impact on availability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-723r-89px-cqxv

11 месяцев назад

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript payload executes in the scope of victim�s browser potentially compromising their data and/or manipulating browser content. This leads to a limited impact on confidentiality and integrity. There is no impact on availability

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-03621

11 месяцев назад

Уязвимость компонента WEBGUI программной интеграционной платформы SAP NetWeaver Application Server ABAP, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-26659

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript payload executes in the scope of victim�s browser potentially compromising their data and/or manipulating browser content. This leads to a limited impact on confidentiality and integrity. There is no impact on availability

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-723r-89px-cqxv

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript payload executes in the scope of victim�s browser potentially compromising their data and/or manipulating browser content. This leads to a limited impact on confidentiality and integrity. There is no impact on availability

CVSS3: 6.1
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-03621

Уязвимость компонента WEBGUI программной интеграционной платформы SAP NetWeaver Application Server ABAP, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.1
0%
Низкий
11 месяцев назад

Уязвимостей на страницу