← Back

CVE-2024-24742

nvd nist
Published: Feb 13, 2024Modified: Nov 21, 2024

JSON object

Loading...
4.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Exploitability: 2.3 / Impact: 1.4
Source: NVD

Description

SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to integrity of the application data after successful exploitation. There is no impact on confidentiality and availability.

Affected (12)

1 product
Crm Webclient Ui
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version s4fnd_102
Version s4fnd_103
Version s4fnd_104
Version s4fnd_105
Version s4fnd_106
Version webcuif_701
Version webcuif_731
Version webcuif_746
Version webcuif_747
Version webcuif_748
Version webcuif_800
Version webcuif_801

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.