SAP CRM WebClient UI XSS Stored XSS via Unsanitized URLs
CVE-2023-30742 Published on May 9, 2023
Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.An attacker could store a malicious URL and lure the victim to click, causing the script supplied by the attacker to execute in the victim user's session. The information from the victim's session could then be modified or read by the attacker.
Vulnerability Analysis
CVE-2023-30742 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2023-30742 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2023-30742
stack.watch emails you whenever new vulnerabilities are published in SAP Customer Relationship Management Webclient Ui or SAP Customer Relationship Management S4fnd. Just hit a watch button to start following.
Affected Versions
SAP_SE SAP CRM (WebClient UI):- Version S4FND 102 is affected.
- Version S4FND 103 is affected.
- Version S4FND 104 is affected.
- Version S4FND 105 is affected.
- Version S4FND 106 is affected.
- Version S4FND 107 is affected.
- Version WEBCUIF 700 is affected.
- Version WEBCUIF 701 is affected.
- Version WEBCUIF 731 is affected.
- Version WEBCUIF 746 is affected.
- Version WEBCUIF 747 is affected.
- Version WEBCUIF 748 is affected.
- Version WEBCUIF 800 is affected.
- Version WEBCUIF 801 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.