Files
CVEs-PoC/2021/CVE-2021-33665.md
2025-09-29 21:09:30 +02:00

24 lines
1.4 KiB
Markdown

### [CVE-2021-33665](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33665)
![](https://img.shields.io/static/v1?label=Product&message=SAP%20NetWeaver%20Application%20Server%20ABAP%20(Applications%20based%20on%20SAP%20GUI%20for%20HTML)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%207.53%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%207.77%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%207.81%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%207.84%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%20KERNEL%20-%207.49%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%20KRNL64NUC%20-%207.49%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%20KRNL64UC%20-%207.49%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Cross%20Site%20Scripting&color=brightgreen)
### Description
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/n0-traces/cve_monitor