Cross-Site Scripting in SAP Contact Center Communication Desktop
CVE-2021-33672
9.6CRITICAL
Summary
A vulnerability in the SAP Contact Center's Communication Desktop component allows for the injection of malicious scripts via chat messages. This issue arises from inadequate encoding, permitting an attacker to execute scripts within the recipient's environment once the message is received. Given the application's use of ActiveX, attackers can potentially execute system-level commands, compromising the confidentiality and integrity of the affected system while also posing risks to its availability.
Affected Version(s)
SAP Contact Center < 700
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved