CVE-2020-6283
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data relating to his or her current session.
SAP Fiori Launchpad no codifica suficientemente las entradas controladas por el usuario y, por lo tanto, permite al atacante inyectar la etiqueta meta en el html launchpad usando el parámetro vulnerable, resultando en una vulnerabilidad de tipo Cross-Site Scripting (XSS) reflejado. Con un ataque con éxito, el atacante puede robar información de autenticación del usuario, tal y como datos relacionados con su sesión actual.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-08 CVE Reserved
- 2020-09-09 CVE Published
- 2023-05-26 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 | 2020-09-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Fiori Launchpad Search vendor "Sap" for product "Fiori Launchpad" | 750 Search vendor "Sap" for product "Fiori Launchpad" and version "750" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Fiori Launchpad Search vendor "Sap" for product "Fiori Launchpad" | 752 Search vendor "Sap" for product "Fiori Launchpad" and version "752" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Fiori Launchpad Search vendor "Sap" for product "Fiori Launchpad" | 753 Search vendor "Sap" for product "Fiori Launchpad" and version "753" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Fiori Launchpad Search vendor "Sap" for product "Fiori Launchpad" | 754 Search vendor "Sap" for product "Fiori Launchpad" and version "754" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Fiori Launchpad Search vendor "Sap" for product "Fiori Launchpad" | 755 Search vendor "Sap" for product "Fiori Launchpad" and version "755" | - |
Affected
|