CVE-2017-9613

MEDIUM

SAP SuccessFactors <b1705.1234962 - XSS

Title source: llm

Description

Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web script or HTML via the file upload functionality.

Scores

CVSS v3 5.4
EPSS 0.0034
EPSS Percentile 56.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
sap/successfactors < b1702p5e.1190658
n/a/n/a
Published Jun 15, 2017
Tracked Since Feb 18, 2026