Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2gh9-j675-j2ff

Опубликовано: 14 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

EPSS

Процентиль: 64%
0.00463
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 3 лет назад

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

EPSS

Процентиль: 64%
0.00463
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79