Vulnerability Details CVE-2023-24525
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.5%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-24525
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.00
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.01
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.02
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.31
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.40
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.48
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.50
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.52
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:8.00
-
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:8.01
-
-