CVE-2017-9613
MEDIUMSAP SuccessFactors <b1705.1234962 - XSS
Title source: llmDescription
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web script or HTML via the file upload functionality.
References (4)
Scores
CVSS v3
5.4
EPSS
0.0034
EPSS Percentile
56.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
sap/successfactors
< b1702p5e.1190658
n/a/n/a
Published
Jun 15, 2017
Tracked Since
Feb 18, 2026