漏洞标题
SAP Commerce (Swagger UI)中的跨站脚本(XSS)漏洞
漏洞描述信息
由于输入验证不足,SAP Commerce(Swagger UI)允许未认证的攻击者从远程来源注入恶意代码,这可以被攻击者利用来执行跨站脚本攻击(XSS)。这可能会对SAP Commerce中的数据机密性、完整性和可用性造成严重影响。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI)
漏洞描述信息
Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)