Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x8gc-wgw2-28c8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could be used by an attacker to build a special url that execute custom JavaScript code when the url is accessed.

SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could be used by an attacker to build a special url that execute custom JavaScript code when the url is accessed.

EPSS

Процентиль: 46%
0.00231
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could be used by an attacker to build a special url that execute custom JavaScript code when the url is accessed.

CVSS3: 6.1
fstec
больше 6 лет назад

Уязвимость модуля BILogon/appService.jsp платформы бизнес-аналитики SAP BusinessObjects Business Intelligence, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 46%
0.00231
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79