Cross-site Scripting Flaw in SAP Internet Graphics Service
CVE-2007-3613

Currently unrated

Key Information:

Vendor

SAP

Vendor
CVE Published:
6 July 2007

What is CVE-2007-3613?

A cross-site scripting vulnerability exists in the ADM:GETLOGFILE function of SAP Internet Graphics Service (IGS). This flaw allows remote attackers to inject arbitrary web scripts or HTML through the PARAMS parameter, potentially compromising the security of the web application and exposing users to attacks such as session hijacking or phishing.

References

EPSS Score

15% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.