Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
2024-07-09T04:15:12.867
2024-11-21T09:23:21.503
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | customer_relationship_management_s4fnd | 102 | Yes |
Application | sap | customer_relationship_management_s4fnd | 103 | Yes |
Application | sap | customer_relationship_management_s4fnd | 104 | Yes |
Application | sap | customer_relationship_management_s4fnd | 105 | Yes |
Application | sap | customer_relationship_management_s4fnd | 106 | Yes |
Application | sap | customer_relationship_management_s4fnd | 107 | Yes |
Application | sap | customer_relationship_management_s4fnd | 108 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 701 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 731 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 746 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 747 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 748 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 800 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 801 | Yes |