CVE-2023-24525
14.02.2023, 04:15
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.
Vendor | Product | Version |
---|---|---|
sap | customer_relationship_management_webclient_ui | 7.00 |
sap | customer_relationship_management_webclient_ui | 7.01 |
sap | customer_relationship_management_webclient_ui | 7.02 |
sap | customer_relationship_management_webclient_ui | 7.31 |
sap | customer_relationship_management_webclient_ui | 7.40 |
sap | customer_relationship_management_webclient_ui | 7.48 |
sap | customer_relationship_management_webclient_ui | 7.50 |
sap | customer_relationship_management_webclient_ui | 7.52 |
sap | customer_relationship_management_webclient_ui | 8.00 |
sap | customer_relationship_management_webclient_ui | 8.01 |
sap | s4fnd | 1.02 |
sap | s4fnd | 1.03 |
𝑥
= Vulnerable software versions