cbcvebase.
CVE-2021-33666
published 2021-06-09

CVE-2021-33666: When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware proliferation.

Affected

2 ranges
VendorProductVersion rangeFixed in
sapcommerce_cloud
sap_sesap_commerce_cloud< 100100
CVE-2021-33666 — Cross-site Scripting | cvebase