CVE-2019-0368

SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
sapCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
sapcustomer_relationship_management_bbpcrm
7.0
sapcustomer_relationship_management_bbpcrm
7.01
sapcustomer_relationship_management_bbpcrm
7.02
sapcustomer_relationship_management_bbpcrm
7.12
sapcustomer_relationship_management_bbpcrm
7.13
sapcustomer_relationship_management_bbpcrm
7.14
sapcustomer_relationship_management_s4crm
1.0
sapcustomer_relationship_management_s4crm
2.0
𝑥
= Vulnerable software versions