CVE-2024-44120

MEDIUM

SAP NetWeaver Enterprise Portal - XSS

Title source: llm
STIX 2.1

Description

SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times out, then the attacker could read and manipulate user content in the browser.

References (2)

Core 2
Core References

Scores

CVSS v3 4.7
EPSS 0.0061
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
SAP_SE/SAP NetWeaver Enterprise Portal 7.50
Published Sep 10, 2024
Tracked Since Feb 18, 2026