CVE-2024-45278

Publication date

2024-10-08 03:21:25

Family

sap

State

PUBLISHED

Description

SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.