Lucene search

K
prionPRIOn knowledge basePRION:CVE-2008-1846
HistoryApr 16, 2008 - 5:05 p.m.

Cross site scripting

2008-04-1617:05:00
PRIOn knowledge base
www.prio-n.com
2

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.8%

The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the “Always Use Secure HTML Editor” (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.

CPENameOperatorVersion
netweaverle7.0

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.8%

Related for PRION:CVE-2008-1846