Cross-Site Scripting Vulnerability in SAP Fiori Launchpad
CVE-2020-6210

4.7MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
10 March 2020

Summary

The SAP Fiori Launchpad in versions 753 and 754 suffers from a reflected Cross-Site Scripting vulnerability due to insufficient encoding of user-controlled inputs. This flaw allows attackers to manipulate parameters to inject malicious meta tags into the launchpad HTML, potentially leading to unauthorized actions or exposure of sensitive information when unsuspecting users interact with the affected application.

Affected Version(s)

SAP Fiori Launchpad < 753 < 753

SAP Fiori Launchpad < 754 < 754

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.