CVE-2022-41266 is a DOM Cross-Site Scripting (XSS) vulnerability in SAP Commerce Webservices 2.0 (Swagger UI) across versions 1905, 2005, 2105, 2011, and 2205, stemming from insufficient input validation. This allows an unauthenticated attacker to execute malicious scripts, potentially stealing user tokens and leading to full account takeover, including access to administrative tools. Rated Medium severity with a CVSS score of 6.1, it requires user interaction and has low impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1905CPE matchmatch criteria | cpe:2.3:a:sap:commerce_webservices_2.0:1905:*:*:*:*:*:*:* | ||
2005CPE matchmatch criteria | cpe:2.3:a:sap:commerce_webservices_2.0:2005:*:*:*:*:*:*:* | ||
2011CPE matchmatch criteria | cpe:2.3:a:sap:commerce_webservices_2.0:2011:*:*:*:*:*:*:* | ||
2105CPE matchmatch criteria | cpe:2.3:a:sap:commerce_webservices_2.0:2105:*:*:*:*:*:*:* | ||
2205CPE matchmatch criteria | cpe:2.3:a:sap:commerce_webservices_2.0:2205:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.