CVE-2024-45278

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Nov 14, 2024
CWE ID 79

Summary

CVE-2024-45278 is a newly identified Cross-Site Scripting (XSS) vulnerability affecting SAP Commerce Backoffice. This issue stems from insufficient input encoding, allowing user-controlled data to be injected maliciously into web pages. An attacker who successfully exploits this flaw can execute scripts in the context of the affected site, potentially leading to confidentiality and integrity concerns for the application. While the impact is currently deemed limited, it is crucial for organizations utilizing SAP Commerce Backoffice to apply the necessary patches or mitigations to protect against XSS attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share