GHSA-cxvr-26hw-h83x
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 7, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.