Improper Neutralization of Input in SAPUI5
CVE-2023-30743
7.1HIGH
Summary
The SAPUI5 framework exhibits a vulnerability due to improper handling of user input, allowing the injection of untrusted CSS into applications. This flaw can disrupt user interaction and potentially enable attackers to read or manipulate user information through phishing methods, especially when URL validation is bypassed. Users of affected SAPUI5 versions should take immediate steps to secure their applications against possible exploits.
Affected Version(s)
SAPUI5 SAP_UI 750
SAPUI5 SAP_UI 754
SAPUI5 SAP_UI 755
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved