Multiple XSS Vulnerabilities in SAP NetWeaver Business Client
CVE-2014-4160
Currently unrated
Summary
The SAP NetWeaver Business Client contains multiple cross-site scripting vulnerabilities within the testcanvas node. These flaws enable remote attackers to execute arbitrary web scripts or HTML by exploiting the title or sap-accessibility parameters, potentially compromising user data and application integrity. Proper input validation and output encoding measures are crucial to mitigate such risks and secure web applications effectively.
References
Timeline
Vulnerability published
Vulnerability Reserved