SAP Note 1484709 - Unauthorized change of displayed contents in CRM_ITIC

Component : Business Transaction -

Solution : https://service.sap.com/sap/support/notes/1484709 (SAP Service marketplace login required)

Key words :
terms reflected cross-site scripting, prerequisites reflected cross-site scripting, reflected cross-site scripting, manipulating crm_itic_adj/session_buffered_frame, inadequate output coding, change displayed data, xss reason, triggered due, current session, administrative rights

Related Notes :

888889Automatic checks for security notes using RSECNOTE