CVE-2020-6272
CVE-2020-6272
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Oct 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
SAP SE · SAP Commerce CloudWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →