Loading HuntDB...

GHSA-2jrj-r8hh-8g59

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to steal user tokens and achieve a full account takeover including access to administrative tools in SAP Commerce.

Related CVEs

Key Information

GHSA ID
GHSA-2jrj-r8hh-8g59
Published
December 13, 2022 3:30 AM
Last Modified
December 15, 2022 6:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.