The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-04-16T17:00:00
Updated: 2024-08-07T08:40:58.785Z
Reserved: 2008-04-16T00:00:00
Link: CVE-2008-1846
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-04-16T17:05:00.000
Modified: 2018-10-11T20:37:41.027
Link: CVE-2008-1846
Redhat
No data.