cve/2018/CVE-2018-17861.md
2024-06-09 00:33:16 +00:00

1.1 KiB

CVE-2018-17861

Description

** UNSUPPORTED WHEN ASSIGNED ** A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

POC

Reference

Github

No PoCs found on GitHub currently.