Dissecting Stored XSS in SAP Concur Open Vulnerability

Dissecting Stored XSS in SAP Concur Open: Event Handler Bypass and Regex Evasion Tactics

Yeasir Arafat

A Synack Red Team member discovered a cross-site scripting vulnerability in SAP Concur Open that could be exploited to hijack sessions, exfiltrate data and more. In this edition of Exploits Explained, Yeasir “zy1l0i2u” Arafat walks us through his discovery of this vuln.

In a recent assessment. I uncovered a Stored Cross-Site Scripting (XSS) vulnerability in SAP Concur Open, a core component of SAP Concur’s travel and expense management ecosystem that affects millions of SAP users. This exploit demonstrates how attackers can leverage obscure event handlers and flawed regex-based input filters to execute malicious scripts, bypassing multiple layers of security controls.

The Layers of Defense Targeted:

  1. SAP Concur Open’s Input Validations: Strong in-place filters designed to block any quotes, HTML tags and event handlers.
  2. Akamai Web Application Firewall (WAF): A robust perimeter defense solution integrated with SAP Concur to detect and block injection attacks.

The Exploit and Its Techniques:

The attack demonstrates how modern XSS payloads evade both application-level filters and WAF defenses through:

Scope of This Post:

This blog post will:

This post offers a deep dive into modern XSS exploitation techniques and highlights the importance of multi-layered security defenses to protect against evolving threats. These techniques, often overlooked by developers and security controls, allowed me to achieve persistent XSS execution within the platform.

About SAP Concur Open:

SAP Concur Open is the API-driven extension of SAP Concur, providing enterprises with advanced expense and travel management capabilities. It can be used to define corporate travel policies and classes. Streamline expense report approvals and audits; configure policies using Concur APIs; and connect with enterprise resource planning (ERP) systems, travel agencies and other third-party services.

Security Layers in SAP Concur Open:

  1. In-Place Input Validation by SAP Concur: