SAP Application Interface (Message Monitoring) - HTML Injection Vulnerability

SAP Application Interface (Message Monitoring) - HTML Injection Vulnerability

CVE-2023-29112 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

Learn more about our Web Application Penetration Testing UK.