SAP CRM WebClient UI XSS via Improper Input Encoding
CVE-2023-29188 Published on May 9, 2023
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker with user level access can read and modify some sensitive information but cannot delete the data.
Vulnerability Analysis
CVE-2023-29188 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2023-29188 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2023-29188
Want to know whenever a new CVE is published for SAP products? stack.watch will email you.
Affected Versions
SAP_SE SAP CRM WebClient UI:- Version SAPSCORE 129 is affected.
- Version S4FND 102 is affected.
- Version S4FND 103 is affected.
- Version S4FND 104 is affected.
- Version S4FND 105 is affected.
- Version S4FND 106 is affected.
- Version S4FND 107 is affected.
- Version WEBCUIF 701 is affected.
- Version WEBCUIF 731 is affected.
- Version WEBCUIF 746 is affected.
- Version WEBCUIF 747 is affected.
- Version WEBCUIF 748 is affected.
- Version WEBCUIF 800 is affected.
- Version WEBCUIF 801 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.