Vulnerabilities > SAP > Fiori Launchpad > 753

DATE CVE VULNERABILITY TITLE RISK
2020-09-09 CVE-2020-6283 Cross-site Scripting vulnerability in SAP Fiori Launchpad
SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
network
sap CWE-79
4.3
2020-03-10 CVE-2020-6210 Cross-site Scripting vulnerability in SAP Fiori Launchpad 753/754
SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.
network
sap CWE-79
4.3