SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
2024-10-08T04:15:08.400
2024-11-14T17:17:12.640
Analyzed
CVSSv3.1: 5.4 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | commerce_backoffice | 2205 | Yes |
| Application | sap | commerce_backoffice | 2211 | Yes |