CVE-2023-39437: SAP Business One

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it delivered to the client, resulting to Cross-site scripting. This could lead to harmful action affecting the Confidentiality, Integrity and Availability of the application.

Affected products

  • SAP Business One: version 10.0 only

Published 2023-08-08. Last modified 2026-06-17.