CVE-2024-47590
An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.76%
- CWE
- CWE-791
- Published
- 2024-11-12
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP Web Dispatcher
- SAP_SE SAP Web Dispatcher
- SAP_SE SAP Web Dispatcher
- SAP_SE SAP Web Dispatcher
- SAP_SE SAP Web Dispatcher
- SAP_SE SAP Web Dispatcher
Weakness type
Related vulnerabilities
- CVE-2026-86206 — Access control filter bypass allows unauthorised access to APIs
- CVE-2026-78140 — Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine
- CVE-2026-75979 — xianrendzw EasyReport SQL Preview Endpoint DesignerController.java previewSqlText special elements in template engine
- CVE-2026-19929 — OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine
- CVE-2026-18632 — langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine
- CVE-2026-11998 — AngularJS XSS via SCE resource URL sanitization bypass
- CVE-2026-48208 — Denial-of-Service via SVG Rendering in Ticket
- CVE-2026-9498 — Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine