CVE-2020-6323

CVE-2020-6323

SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions – 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that will be both reflected immediately and also be persisted and returned in further access to the system, resulting in Cross Site Scripting.

Source: CVE-2020-6323

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다