Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g64w-x6g2-6j38

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data relating to his or her current session.

SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data relating to his or her current session.

EPSS

Процентиль: 58%
0.00361
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data relating to his or her current session.

EPSS

Процентиль: 58%
0.00361
Низкий