CVE-2024-22130
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Feb 13, 2024
CWE ID 79
Summary
CVE-2024-22130 is a Cross-Site Scripting (XSS) vulnerability affecting various versions of SAP CRM WebClient UI, including S4FND 102 to 108 and WEBCUIF 700 to 801. The root cause is insufficient input encoding on user-controlled data used in print preview functions. An attacker with minimal privileges can exploit this flaw to inject and execute malicious scripts, potentially leading to data confidentiality and integrity breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share