Improper Neutralization of Input in SAPUI5
CVE-2023-30743

7.1HIGH

Key Information:

Vendor
SAP
Status
Vendor
CVE Published:
9 May 2023

Summary

The SAPUI5 framework exhibits a vulnerability due to improper handling of user input, allowing the injection of untrusted CSS into applications. This flaw can disrupt user interaction and potentially enable attackers to read or manipulate user information through phishing methods, especially when URL validation is bypassed. Users of affected SAPUI5 versions should take immediate steps to secure their applications against possible exploits.

Affected Version(s)

SAPUI5 SAP_UI 750

SAPUI5 SAP_UI 754

SAPUI5 SAP_UI 755

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.