CVE-2019-0369

SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:financial_consolidation:10.0:*:*:*:*:*:*:*
cpe:2.3:a:sap:financial_consolidation:10.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-10-08 20:15

Updated : 2024-02-04 20:39


NVD link : CVE-2019-0369

Mitre link : CVE-2019-0369

CVE.ORG link : CVE-2019-0369


JSON object : View

Products Affected

sap

  • financial_consolidation
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')