PT-2020-19001 · Google+1 · Angularjs+1
Published
2020-03-10
·
Updated
2020-03-11
·
CVE-2020-6200
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Commerce (SmartEdit Extension) versions 6.6, 6.7, 1808, 1811
Description
The issue is related to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.
Recommendations
For versions 6.6, 6.7, 1808, 1811, consider disabling the angularjs template injection functionality until a patch is available.
Restrict access to the templating facilities of the angular framework to minimize the risk of exploitation.
Avoid using the vulnerable angularjs template injection in the affected SAP Commerce (SmartEdit Extension) until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Angularjs
Sap Commerce