Improper Neutralization of Input in SAPUI5
CVE-2023-30743

6.1MEDIUM

Key Information:

Vendor
SAP
Status
Vendor
CVE Published:
9 May 2023

Summary

Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’s interaction with the application. Further, in the absence of URL validation by the application, the vulnerability could lead to the attacker reading or modifying user’s information through phishing attack.

Affected Version(s)

SAPUI5 SAP_UI 750

SAPUI5 SAP_UI 754

SAPUI5 SAP_UI 755

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.