Loading HuntDB...

GHSA-xqh8-8m3p-c72r

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details


SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application. 

Related CVEs

Key Information

GHSA ID
GHSA-xqh8-8m3p-c72r
Published
May 14, 2024 6:31 PM
Last Modified
May 14, 2024 6:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 7, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.