SAP Commerce
cpe:2.3:a:sap:commerce:*:*:*:*:*:*:*
- 6.6
- 6.7
- 1808
- 1811
A client-side AngularJS template injection vulnerability, which is a variant of Cross-Site Scripting (XSS), has been identified in the SAP Commerce SmartEdit Extension. This issue affects versions 6.6, 6.7, 1808, and 1811. The vulnerability arises from the exploitation of the templating capabilities of the Angular framework.
Exploitation of this vulnerability allows for client-side AngularJS template injection, leading to a Cross-Site Scripting (XSS) vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.