CVE Published: 15/02/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: sap |
Vendor: SAP SE |
Product: SAP WebIntelligence BILaunchPad (Enterprise) Status : PUBLISHED
CVE-2019-0262 Description
SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability.