Loading HuntDB...

GHSA-9659-6f28-gj3x

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Reflected Cross Site Scripting.

Related CVEs

Key Information

GHSA ID
GHSA-9659-6f28-gj3x
Published
May 24, 2022 5:10 PM
Last Modified
April 4, 2024 2:49 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 26, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.