GHSA-mh58-mm5c-49p8
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 26, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.