CVE Published: 10/03/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: sap |
Vendor: SAP SE |
Product: SAP Fiori Launchpad Status : PUBLISHED
CVE-2020-6210 Description
SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.