CVE-2022-41266 Information
Dec 14, 2022
cve
Description
Due to a lack of proper input validation SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905 2005 2105 2011 2205 allows malicious inputs from untrusted sources which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack. As a result an attacker may be able to steal user tokens and achieve a full account takeover including access to administrative tools in SAP Commerce.
Reference
https://launchpad.support.sap.com/#/notes/3248255 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Share on: