Cross-Site Scripting Vulnerability in SAP Fiori Launchpad
CVE-2020-6210
4.7MEDIUM
What is CVE-2020-6210?
The SAP Fiori Launchpad in versions 753 and 754 suffers from a reflected Cross-Site Scripting vulnerability due to insufficient encoding of user-controlled inputs. This flaw allows attackers to manipulate parameters to inject malicious meta tags into the launchpad HTML, potentially leading to unauthorized actions or exposure of sensitive information when unsuspecting users interact with the affected application.
Affected Version(s)
SAP Fiori Launchpad < 753 < 753
SAP Fiori Launchpad < 754 < 754