Vulnerabilities > SAP > Fiori Launchpad > 753
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-09-09 | CVE-2020-6283 | Cross-site Scripting vulnerability in SAP Fiori Launchpad SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | 6.1 |
2020-03-10 | CVE-2020-6210 | Cross-site Scripting vulnerability in SAP Fiori Launchpad 753/754 SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability. | 6.1 |