Cross-Site Scripting Vulnerability in SAP Fiori Launchpad
CVE-2020-6210

4.7MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 March 2020

What is CVE-2020-6210?

The SAP Fiori Launchpad in versions 753 and 754 suffers from a reflected Cross-Site Scripting vulnerability due to insufficient encoding of user-controlled inputs. This flaw allows attackers to manipulate parameters to inject malicious meta tags into the launchpad HTML, potentially leading to unauthorized actions or exposure of sensitive information when unsuspecting users interact with the affected application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SAP Fiori Launchpad < 753 < 753

SAP Fiori Launchpad < 754 < 754

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.