vendor:
B2B OR B2C CRM
by:
Richard Alviarez
8.8
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: B2B OR B2C CRM
Affected Version From: 2.x
Affected Version To: 4.x
Patch Exists: YES
Related CWE: N/A
CPE: SAP:B2B_OR_B2C_CRM
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
SAP B2B / B2C CRM 2.x < 4.x - Local File Inclusion
A possible attacker can take advantage of this vulnerability to obtain confidential information of the platform, as well as the possibility of writing in the logs of the registry in order to get remote execution of commands and take control of the system.
Mitigation:
Ensure that user input is properly validated and sanitized to prevent malicious code from being executed.