← voltar
CVE-2024-37178

Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation

CVSS 5 MEDIUMEPSS 0.3%CWE-79
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
11 jun 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can cause limited impact to confidentiality of the application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →