encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)
vulnerability causing low impact on confidentiality and integrity of the
application.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39178 | SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact on confidentiality and integrity of the application. |
Thu, 12 Sep 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap commerce Backoffice |
|
| CPEs | cpe:2.3:a:sap:commerce_backoffice:hy_com_2205:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap commerce Backoffice |
Tue, 13 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact on confidentiality and integrity of the application. | |
| Title | Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-13T14:44:24.355Z
Reserved: 2024-07-22T08:06:52.677Z
Link: CVE-2024-41735
Updated: 2024-08-13T14:44:20.609Z
Status : Analyzed
Published: 2024-08-13T04:15:09.323
Modified: 2024-09-12T13:53:32.993
Link: CVE-2024-41735
No data.
OpenCVE Enrichment
No data.
EUVD