Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP CRM Mail Form Editor, SAP security note 2519135

SAP Note 2519135

SAP security note 2519135, "Cross-Site Scripting (XSS) Vulnerability in SAP CRM Mail Form Editor", is a note released on October 10, 2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Marketing > Direct Mailing (CRM-MKT-ML)
Released onOctober 10, 2017

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability has been identified in the SAP CRM Mail Form Editor. The vulnerability arises due to insufficient encoding of user-controlled inputs, which can lead to unauthorized actions such as defacement of content, theft of authentication information, and user impersonation.

Solution

To mitigate this vulnerability, implement the support package or the patch referenced by this SAP note. The fix encodes the subject line when the mail form is displayed in the preview functionality.

CVSS

Score 5.4 / 10 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected components

  • Customer Relationship Management > Marketing > Direct Mailing (CRM-MKT-ML): Versions 700 to 714

Full note on SAP: SAP Support Launchpad note 2519135

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More