SAP CRM WebClient UI XSS Stored XSS via Unsanitized URLs
CVE-2023-30742 Published on May 9, 2023

Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.An attacker could store a malicious URL and lure the victim to click, causing the script supplied by the attacker to execute in the victim user's session. The information from the victim's session could then be modified or read by the attacker.

NVD

Vulnerability Analysis

CVE-2023-30742 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
CHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
NONE

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2023-30742 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2023-30742

stack.watch emails you whenever new vulnerabilities are published in SAP Customer Relationship Management Webclient Ui or SAP Customer Relationship Management S4fnd. Just hit a watch button to start following.

 
 

Affected Versions

SAP_SE SAP CRM (WebClient UI):

Exploit Probability

EPSS
0.44%
Percentile
62.70%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.