Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Some Fields are susceptible to Cross-site scripting., SAP security note 1334244

Description

You create a shopping cart and specify Item description having javascript content. Now if your SC has error, then the error message content would be wrongly display and the behaviour would be that of how the item description javascript is executed.

Available fix and Supported packages

  • SRM_SERVER | 500 | 500
  • SRM_SERVER 500 | SAPKIBKS15 |

Affected component

    SRM-EBP-TEC-ITS
    ITS and Web files

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected]

URL

https://launchpad.support.sap.com/#/notes/1334244

TAGS

#BBPSC01
#BBPSC02
#Description
#XSS
#cross-site-scripting
#Attachment

More to explorer