← Back

CVE-2024-22130

nvd nist
Published: Feb 13, 2024Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEBCUIF 701, WEBCUIF 730, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. An attacker with low privileges can cause limited impact to confidentiality and integrity of the appliaction data after successful exploitation.

Affected (16)

1 product
Crm Webclient Ui
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version s4fnd_102
Version s4fnd_103
Version s4fnd_104
Version s4fnd_105
Version s4fnd_106
Version s4fnd_107
Version s4fnd_108
Version webcuif_700
Version webcuif_701
Version webcuif_730
Version webcuif_731
Version webcuif_746
Version webcuif_747
Version webcuif_748
Version webcuif_800
Version webcuif_801

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.