Stored Cross-Site Scripting Vulnerability in SAP Business Objects Business Intelligence
CVE-2020-6300
4.8MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 August 2020
What is CVE-2020-6300?
A vulnerability exists in SAP Business Objects Business Intelligence Platform's Central Management Console, where an attacker with administrator privileges can exploit insufficient encoding of user-controlled input in the RecycleBin feature. This flaw enables the execution of malicious scripts in the context of other users, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
SAP Business Objects Business Intelligence Platform (Central Management Console) < 4.2 < 4.2
SAP Business Objects Business Intelligence Platform (Central Management Console) < 4.3 < 4.3