PT-2024-30961 · Sap · Sap Netweaver Enterprise Portal

Published

2024-09-09

·

Updated

2025-03-10

·

CVE-2024-44120

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Enterprise Portal (affected versions not specified)
Description The issue is related to reflected cross-site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user into clicking it. If the victim clicks on this crafted URL before it times out, the attacker could read and manipulate user content in the browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44120

Affected Products

Sap Netweaver Enterprise Portal