Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.
2024-07-09T04:15:13.127
2024-11-21T09:23:21.650
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | customer_relationship_management_s4fnd | 102 | Yes |
Application | sap | customer_relationship_management_s4fnd | 103 | Yes |
Application | sap | customer_relationship_management_s4fnd | 104 | Yes |
Application | sap | customer_relationship_management_s4fnd | 105 | Yes |
Application | sap | customer_relationship_management_s4fnd | 106 | Yes |
Application | sap | customer_relationship_management_s4fnd | 107 | Yes |
Application | sap | customer_relationship_management_s4fnd | 108 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 701 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 731 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 746 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 747 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 748 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 800 | Yes |
Application | sap | customer_relationship_management_webclient_ui | 801 | Yes |