An attacker can change the content of an SAP Commerce -...
High severity
Unreviewed
Published
Oct 12, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Oct 11, 2022
Published to the GitHub Advisory Database
Oct 12, 2022
Last updated
Jan 27, 2023
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts. A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.
References