Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode user-controlled inputs, this makes it possible for an attacker to send unwanted scripts to the browser of the victim using unwanted input and execute malicious code there, resulting in Cross-Site Scripting (XSS) vulnerability.
2019-06-12T17:29:03.560
2024-11-21T04:16:39.977
Modified
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | r\/3_enterprise | 600 | Yes |
Application | sap | r\/3_enterprise | 602 | Yes |
Application | sap | r\/3_enterprise | 603 | Yes |
Application | sap | r\/3_enterprise | 604 | Yes |
Application | sap | r\/3_enterprise | 605 | Yes |
Application | sap | r\/3_enterprise | 606 | Yes |
Application | sap | r\/3_enterprise | 616 | Yes |
Application | sap | r\/3_enterprise | 617 | Yes |