Loading HuntDB...

GHSA-cxvr-26hw-h83x

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.

Related CVEs

Key Information

GHSA ID
GHSA-cxvr-26hw-h83x
Published
January 14, 2025 3:31 AM
Last Modified
January 14, 2025 3:31 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 7, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.