SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2751806 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-10-08 20:15
Updated : 2024-02-28 17:28
NVD link : CVE-2019-0368
Mitre link : CVE-2019-0368
CVE.ORG link : CVE-2019-0368
JSON object : View
Products Affected
sap
- customer_relationship_management_bbpcrm
- customer_relationship_management_s4crm
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')