Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mxc-g6f2-mx4g

Опубликовано: 07 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.

BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.

EPSS

Процентиль: 36%
0.00149
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
nvd
больше 3 лет назад

BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.

EPSS

Процентиль: 36%
0.00149
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79