Loading HuntDB...

GHSA-w4g5-mcc7-3767

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.

Related CVEs

Key Information

GHSA ID
GHSA-w4g5-mcc7-3767
Published
May 24, 2022 5:38 PM
Last Modified
May 24, 2022 5:38 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 25, 2025 8:46 PM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.