Cross-Site Scripting Vulnerability in SAP Fiori Launchpad
CVE-2020-6210
4.7MEDIUM
Summary
The SAP Fiori Launchpad in versions 753 and 754 suffers from a reflected Cross-Site Scripting vulnerability due to insufficient encoding of user-controlled inputs. This flaw allows attackers to manipulate parameters to inject malicious meta tags into the launchpad HTML, potentially leading to unauthorized actions or exposure of sensitive information when unsuspecting users interact with the affected application.
Affected Version(s)
SAP Fiori Launchpad < 753 < 753
SAP Fiori Launchpad < 754 < 754
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved