Cross-Site Scripting Vulnerability in SAPUI5 and OpenUI5
CVE-2019-0281
6.1MEDIUM
What is CVE-2019-0281?
SAPUI5 and OpenUI5 versions prior to 1.38.39, 1.44.39, 1.52.25, 1.60.6, and 1.63.0 are susceptible to a Cross-Site Scripting vulnerability due to insufficient encoding of user-controlled inputs. This weakness may allow attackers to inject malicious scripts into web pages viewed by end-users, compromising the security of web applications based on these frameworks. It is essential for developers to update their versions and implement proper input handling to mitigate risks.
Affected Version(s)
OpenUI5 1.38.39
OpenUI5 1.44.39
OpenUI5 1.52.25