CVE-2020-6210

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/03/2020
Last modified:
11/03/2020

Description

SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:fiori_launchpad:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:fiori_launchpad:754:*:*:*:*:*:*:*