Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29188


SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker with user level access can read and modify some sensitive information but cannot delete the data.


Published

2023-05-09T01:15:08.943

Last Modified

2024-11-21T07:56:40.970

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap customer_relationship_management_webclient_ui 7.01 Yes
Application sap customer_relationship_management_webclient_ui 7.31 Yes
Application sap customer_relationship_management_webclient_ui 7.46 Yes
Application sap customer_relationship_management_webclient_ui 7.47 Yes
Application sap customer_relationship_management_webclient_ui 7.48 Yes
Application sap customer_relationship_management_webclient_ui 8.00 Yes
Application sap customer_relationship_management_webclient_ui 8.01 Yes
Application sap s4fnd 1.02 Yes
Application sap s4fnd 102 Yes
Application sap s4fnd 103 Yes
Application sap s4fnd 104 Yes
Application sap s4fnd 105 Yes
Application sap s4fnd 106 Yes
Application sap s4fnd 107 Yes
Application sap sapscore 129 Yes

References