ZeroHour

CVE-2024-37174

CVSS 3.1
6.1 medium
EPSS
<1%p17
Published
()
Modified
Description

Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.

Vendors
sap
Products
customer relationship management s4fnd, customer relationship management webclient ui
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.