CVE-2023-24525: SAP Customer Relationship Management Webclient UI
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.
Affected products
- SAP Customer Relationship Management Webclient UI: version 7.00 only; version 7.01 only; version 7.02 only; version 7.31 only; version 7.40 only; version 7.48 only; …
- SAP s4fnd: version 1.02 only; version 1.03 only
Published 2023-02-14. Last modified 2026-06-17.