CVE-2020-6272: XSS
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6272?
The severity of CVE-2020-6272 is classified as medium due to the potential for script injection by authenticated users.
How do I fix CVE-2020-6272?
To fix CVE-2020-6272, upgrade your SAP Commerce Cloud to a version that has applied the necessary security patches.
What versions of SAP Commerce Cloud are affected by CVE-2020-6272?
CVE-2020-6272 affects SAP Commerce Cloud versions 1808, 1811, 1905, and 2005.
What kind of attack is possible with CVE-2020-6272?
CVE-2020-6272 allows an authenticated content manager to inject malicious scripts into web CMS components.
Is user authentication required to exploit CVE-2020-6272?
Yes, authentication is required to exploit CVE-2020-6272, as it involves an authorized content manager.