CVE-2020-6272
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.
SAP Commerce Cloud versiones - 1808, 1811, 1905, 2005, no codifican suficientemente las entradas del usuario, lo que permite a un administrador de contenido autenticado y autorizado inyectar un script malicioso en varios componentes del CMS web. Estos puede ser guardado y activado posteriormente, si se visita una página web afectada, resultando en una vulnerabilidad de tipo Cross-Site Scripting (XSS)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-08 CVE Reserved
- 2020-10-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196 | 2020-10-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Commerce Cloud Search vendor "Sap" for product "Commerce Cloud" | 1808 Search vendor "Sap" for product "Commerce Cloud" and version "1808" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Commerce Cloud Search vendor "Sap" for product "Commerce Cloud" | 1811 Search vendor "Sap" for product "Commerce Cloud" and version "1811" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Commerce Cloud Search vendor "Sap" for product "Commerce Cloud" | 1905 Search vendor "Sap" for product "Commerce Cloud" and version "1905" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Commerce Cloud Search vendor "Sap" for product "Commerce Cloud" | 2005 Search vendor "Sap" for product "Commerce Cloud" and version "2005" | - |
Affected
|