SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times out, then the attacker could read and manipulate user content in the browser.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Sep 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times out, then the attacker could read and manipulate user content in the browser. | |
Title | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-09-10T04:26:46.558Z
Updated: 2024-09-10T13:21:19.086Z
Reserved: 2024-08-20T20:22:59.937Z
Link: CVE-2024-44120
Vulnrichment
Updated: 2024-09-10T13:21:15.659Z
NVD
Status : Awaiting Analysis
Published: 2024-09-10T05:15:11.247
Modified: 2024-09-10T12:09:50.377
Link: CVE-2024-44120
Redhat
No data.