Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a successful attack, a victim opens the report, and the malicious script gets executed in the victim's browser, resulting in a Stored Cross-Site Scripting (XSS) vulnerability.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
SAP Enterprise Portal 跨站脚本漏洞
Vulnerability Description
SAP Enterprise Portal是德国思爱普(SAP)公司的一个应用软件。一个综合性的集成和应用程序平台,可促进跨组织和技术边界的人员、信息和业务流程的一致性。 SAP Enterprise Portal存在跨站脚本漏洞,该漏洞源于攻击者可利用该漏洞可以制造恶意数据并将其打印到报告中。
CVSS Information
N/A
Vulnerability Type
N/A