CVE Published: 08/01/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: sap |
Vendor: SAP SE |
Product: SAP Commerce (ex. SAP Hybris Commerce) Status : PUBLISHED
CVE-2019-0238 Description
SAP Commerce (previously known as SAP Hybris Commerce), before version 6.7, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.