CVE-2018-2410: XSS
Published Apr 10, 2018
·Updated
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.
Affected Software
2 affected components
SAP Business One=9.2
SAP Business One=9.3
Event History
Apr 10, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-2410.
2
What is the severity of CVE-2018-2410?
The severity of CVE-2018-2410 is medium with a CVSS score of 5.4.
3
What is the affected software?
The affected software is SAP Business One version 9.2 and 9.3.
4
How does the vulnerability manifest?
The vulnerability manifests as a Cross-Site Scripting (XSS) vulnerability.
5
Are there any references for CVE-2018-2410?
Yes, there are references available for CVE-2018-2410. You can find them at the following links: [SecurityFocus](http://www.securityfocus.com/bid/103704), [SAP Security Patch Day](https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/), [SAP Support Note](https://launchpad.support.sap.com/#/notes/2582870)