#VU52500 Improper input validation in Oracle Commerce Merchandising - CVE-2020-27193
Published: April 23, 2021
Oracle Commerce Merchandising
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Experience Manager, Business Control Center (CKEditor) component in Oracle Commerce Merchandising. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.