CVE Database
/

CVE-2019-0308

Back to search

CVE-2019-0308

Published: Jun 12, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.

VendorProductVersions

SAP SE

SAP E-Commerce (Business-to-Consumer application)

affected
< 7.3
affected
< 7.31
affected
< 7.32
affected
< 7.33
affected
< 7.54

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now