CVE Database
/

CVE-2020-6283

Back to search

CVE-2020-6283

Published: Sep 9, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

4.8

MEDIUM

Description

SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data relating to his or her current session.

VendorProductVersions

SAP SE

SAP Fiori(Launchpad)

affected
< 750
affected
< 752
affected
< 753
affected
< 754
affected
< 755

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now