Description
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-27422 | SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability. |
References
History
No history.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-04T08:55:22.297Z
Reserved: 2020-01-08T00:00:00.000Z
Link: CVE-2020-6272
No data.
Status : Modified
Published: 2020-10-15T02:15:12.530
Modified: 2024-11-21T05:35:25.123
Link: CVE-2020-6272
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD