Improper Neutralization of Input in SAPUI5
CVE-2023-30743
7.1HIGH
What is CVE-2023-30743?
The SAPUI5 framework exhibits a vulnerability due to improper handling of user input, allowing the injection of untrusted CSS into applications. This flaw can disrupt user interaction and potentially enable attackers to read or manipulate user information through phishing methods, especially when URL validation is bypassed. Users of affected SAPUI5 versions should take immediate steps to secure their applications against possible exploits.
Affected Version(s)
SAPUI5 SAP_UI 750
SAPUI5 SAP_UI 754
SAPUI5 SAP_UI 755