CVE-2024-47590
published 2024-11-12CVE-2024-47590: An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.77%
51.3th percentile
An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_web_dispatcher | — | — |
| sap_se | sap_web_dispatcher | — | — |
| sap_se | sap_web_dispatcher | — | — |
| sap_se | sap_web_dispatcher | — | — |
| sap_se | sap_web_dispatcher | — | — |
| sap_se | sap_web_dispatcher | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-12
Published