PT-2020-19067 · Sap · Sap Commerce Cloud

Published

2020-10-15

·

Updated

2020-10-19

·

CVE-2020-6272

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Commerce Cloud versions 1808, 1811, 1905, 2005
Description The issue arises from insufficient encoding of user inputs, allowing an authenticated and authorized content manager to inject malicious script into several web CMS components. These scripts can be saved and later triggered when an affected web page is visited, resulting in a Cross-Site Scripting (XSS) issue.
Recommendations For SAP Commerce Cloud version 1808, update the input encoding mechanism to prevent malicious script injection. For SAP Commerce Cloud version 1811, update the input encoding mechanism to prevent malicious script injection. For SAP Commerce Cloud version 1905, update the input encoding mechanism to prevent malicious script injection. For SAP Commerce Cloud version 2005, update the input encoding mechanism to prevent malicious script injection.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6272

Affected Products

Sap Commerce Cloud