CVE-2024-45278
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-45278 is a newly identified Cross-Site Scripting (XSS) vulnerability affecting SAP Commerce Backoffice. This issue stems from insufficient input encoding, allowing user-controlled data to be injected maliciously into web pages. An attacker who successfully exploits this flaw can execute scripts in the context of the affected site, potentially leading to confidentiality and integrity concerns for the application. While the impact is currently deemed limited, it is crucial for organizations utilizing SAP Commerce Backoffice to apply the necessary patches or mitigations to protect against XSS attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.