Reflected Cross Site Scripting Vulnerability in SAP Commerce by SAP
CVE-2020-6201
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 March 2020
What is CVE-2020-6201?
SAP Commerce, specifically in the Testweb Extension across multiple versions, lacks adequate encoding of user-controlled inputs. This vulnerability allows certain GET URL parameters to be reflected in HTTP responses without proper escaping or sanitization, which can lead to reflected cross site scripting attacks. Malicious users could exploit this weakness to inject arbitrary scripts into pages viewed by other users, potentially compromising sensitive information and overall web application security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Commerce Cloud (Testweb Extension) < 6.6 < 6.6
SAP Commerce Cloud (Testweb Extension) < 6.7 < 6.7
SAP Commerce Cloud (Testweb Extension) < 1808 < 1808
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved