The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.
2020-03-10T21:15:14.107
2024-11-21T05:35:17.177
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | commerce_cloud | 6.6 | Yes |
Application | sap | commerce_cloud | 6.7 | Yes |
Application | sap | commerce_cloud | 1808 | Yes |
Application | sap | commerce_cloud | 1811 | Yes |