First published: Tue Aug 13 2024(Updated: )
SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact on confidentiality and integrity of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Commerce Backoffice | =hy_com_2205 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41735 has a low impact on confidentiality and integrity due to the Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2024-41735, ensure that user-controlled inputs in SAP Commerce Backoffice are properly encoded.
CVE-2024-41735 is caused by insufficient encoding of user-controlled inputs in SAP Commerce Backoffice.
The affected version of SAP Commerce Backoffice is hy_com_2205.
CVE-2024-41735 can lead to Cross-Site Scripting attacks, potentially compromising user data and application integrity.