CVE-2019-0308

MEDIUM

SAP E-Commerce 7.3, 7.31, 7.32, 7.33, 7.54 - Authenticated Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2773493

Scores

CVSS v3 6.8
EPSS 0.0022
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

Details

CWE
CWE-79
Status published
Products (5)
sap/e-commerce 7.30
sap/e-commerce 7.31
sap/e-commerce 7.32
sap/e-commerce 7.33
sap/e-commerce 7.54
Published Jun 12, 2019
Tracked Since Feb 18, 2026