CVE-2018-2505

SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in versions (SAP Hybris Commerce, versions 6.2, 6.3, 6.4, 6.5, 6.6, 6.7).
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:hybris:6.2:*:*:*:*:*:*:*
cpe:2.3:a:sap:hybris:6.3:*:*:*:*:*:*:*
cpe:2.3:a:sap:hybris:6.4:*:*:*:*:*:*:*
cpe:2.3:a:sap:hybris:6.5:*:*:*:*:*:*:*
cpe:2.3:a:sap:hybris:6.6:*:*:*:*:*:*:*
cpe:2.3:a:sap:hybris:6.7:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-12-11 22:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-2505

Mitre link : CVE-2018-2505

CVE.ORG link : CVE-2018-2505


JSON object : View

Products Affected

sap

  • hybris
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')