The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T08:40:58.785Z
Reserved: 2008-04-16T00:00:00
Link: CVE-2008-1846

No data.

Status : Modified
Published: 2008-04-16T17:05:00.000
Modified: 2024-11-21T00:45:29.393
Link: CVE-2008-1846

No data.