cbcvebase.
CVE-2020-6272
published 2020-10-15

CVE-2020-6272: SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.

Affected

8 ranges
VendorProductVersion rangeFixed in
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sap_sesap_commerce_cloud< 18081808
sap_sesap_commerce_cloud< 18111811
sap_sesap_commerce_cloud< 19051905
sap_sesap_commerce_cloud< 20052005