CVE-2022-41204
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a mani
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts.
A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.
HIGH · CVSS 8.8
EPSS 0.00418
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0