VYPR
Medium severity6.8NVD Advisory· Published Jun 12, 2019· Updated Jun 17, 2026

CVE-2019-0308

CVE-2019-0308

Description

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.

Affected products

7
  • SAP/E-Commerce6 versions
    cpe:2.3:a:sap:e-commerce:7.30:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:sap:e-commerce:7.30:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:e-commerce:7.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:e-commerce:7.32:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:e-commerce:7.33:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:e-commerce:7.54:*:*:*:*:*:*:*
    • (no CPE)range: 7.3, 7.31, 7.32, 7.33, 7.54
  • SAP SE/SAP E-Commerce (Business-to-Consumer application)v5
    Range: < 7.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.