Unrated severityNVD Advisory· Published Jul 9, 2024· Updated Aug 2, 2024
[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
CVE-2024-37174
Description
Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: S4FND 102
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.