Description
You create a shopping cart and specify Item description having javascript content. Now if your SC has error, then the error message content would be wrongly display and the behaviour would be that of how the item description javascript is executed.
Available fix and Supported packages
- SRM_SERVER | 500 | 500
- SRM_SERVER 500 | SAPKIBKS15 |
Affected component
- SRM-EBP-TEC-ITS
ITS and Web files
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1334244