HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-27434
发布日期2025-03-11T00:39:01.831Z
更新日期2025-03-12T04:00:31.592Z
状态PUBLISHED
受影响的供应商SAP_SE
受影响的产品SAP Commerce (Swagger UI)
描述Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.

参考链接:

Image Additional Image