CVE Published: 10/03/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: sap |
Vendor: SAP SE |
Product: SAP Commerce Cloud (Testweb Extension) Status : PUBLISHED
CVE-2020-6201 Description
The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Reflected Cross Site Scripting.