SAP Customer Relationship Management (CRM) WebClient UI Cross Site Scripting Vulnerability
BID:103002
CVE-2018-2364 |Info
SAP Customer Relationship Management (CRM) WebClient UI Cross Site Scripting Vulnerability
| Bugtraq ID: | 103002 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-2364 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2018 12:00AM |
| Updated: | Feb 13 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP Customer Relationship Management 8.01 SAP Customer Relationship Management 8.00 SAP Customer Relationship Management 7.48 SAP Customer Relationship Management 7.47 SAP Customer Relationship Management 7.46 SAP Customer Relationship Management 7.31 SAP Customer Relationship Management 7.01 |
| Not Vulnerable: | |
Discussion
SAP Customer Relationship Management (CRM) WebClient UI Cross Site Scripting Vulnerability
SAP Customer Relationship Management (CRM) is prone to a cross-site scripting vulnerability.
Remote attackers can exploit this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
SAP Customer Relationship Management (CRM) is prone to a cross-site scripting vulnerability.
Remote attackers can exploit this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.