cbcvebase.
CVE-2025-42920
published 2025-09-09

CVE-2025-42920: Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and…

PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.24%
15.3th percentile
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim clicks on the link, the injected input is processed during the page generation, resulting in the execution of malicious content. This execution allows the attacker to access and modify information within the victim's browser scope, impacting confidentiality and integrity, while availability remains unaffected.

Affected

6 ranges
VendorProductVersion rangeFixed in
sapsupplier_relationship_management
sap_sesap_supplier_relationship_management
sap_sesap_supplier_relationship_management
sap_sesap_supplier_relationship_management
sap_sesap_supplier_relationship_management
sap_sesap_supplier_relationship_management
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.