Cross-Site Scripting Vulnerability in SAP Afaria 7
CVE-2015-6663
Currently unrated
Summary
A cross-site scripting (XSS) vulnerability exists in the Client form on the Device Inspector page of SAP Afaria 7. This flaw enables remote attackers to inject malicious web scripts or HTML code via specially crafted client name data. Exploiting this vulnerability can compromise user security, allowing attackers to potentially hijack user sessions or execute unauthorized actions within the application. Security practitioners should take immediate action to safeguard against this vulnerability by implementing the appropriate security patches and configurations.
References
Timeline
Vulnerability published
Vulnerability Reserved