CVE-2024-47590
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Nov 12, 2024
CWE ID 791
Summary
CVE-2024-47590 is a newly disclosed cybersecurity vulnerability that allows unauthenticated attackers to create malicious links. When an authenticated user clicks on this link, the input data is utilized by the web page generation process. The resulting content, if executed in the user's browser (XXS), can lead to arbitrary code execution. Alternatively, if transmitted to another server (SSRF), it can enable the attacker to execute code on that server, resulting in a complete compromise of confidentiality, integrity, and availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SAP Web Dispatcher
Affected Vendors
- SAP SE