CVE-2023-24525: XSS
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24525?
The severity of CVE-2023-24525 is medium with a CVSS score of 5.4.
Which versions of SAP CRM WebClient UI are affected by CVE-2023-24525?
Versions WEBCUIF 748, 800, 801, S4FND 102, 103 of SAP CRM WebClient UI are affected by CVE-2023-24525.
What is the impact of CVE-2023-24525?
Successful exploitation of CVE-2023-24525 can cause limited impact on the confidentiality of the application.
How can I fix or mitigate CVE-2023-24525?
To fix CVE-2023-24525, apply the necessary patches and updates provided by SAP.
Where can I find more information about CVE-2023-24525?
You can find more information about CVE-2023-24525 in the SAP Support Portal and the SAP security advisory.