SAP security note 2519135, "Cross-Site Scripting (XSS) Vulnerability in SAP CRM Mail Form Editor", is a note released on October 10, 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Cross-Site Scripting (XSS) vulnerability has been identified in the SAP CRM Mail Form Editor. The vulnerability arises due to insufficient encoding of user-controlled inputs, which can lead to unauthorized actions such as defacement of content, theft of authentication information, and user impersonation.
Solution
To mitigate this vulnerability, implement the support package or the patch referenced by this SAP note. The fix encodes the subject line when the mail form is displayed in the preview functionality.
CVSS
Score 5.4 / 10 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected components
- Customer Relationship Management > Marketing > Direct Mailing (CRM-MKT-ML): Versions 700 to 714
Full note on SAP: SAP Support Launchpad note 2519135
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




