Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. Information maintained in the victim's web browser can be read, modified, and sent to the attacker. The malicious code cannot significantly impact the victim's browser and the victim can easily close the browser tab to terminate it.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SAP Fiori 跨站脚本漏洞
Vulnerability Description
SAP Fiori是德国思爱普(SAP)公司的一套为SAP应用程序提供用户体验(UX)的设计系统,它为设计人员和开发人员提供了一套工具和指南,能够快速地开发适用于任何平台的应用,为创建者和用户提供一致、创新的体验。SAP Fiori Launchpad是SAP Fiori应用程序的入口(Shell),它为应用程序提供导航、个性化、嵌入式支持和应用程序配置等服务。 SAP Fiori Launchpad 750版本至755版本存在跨站脚本漏洞,该漏洞源于News tile 不足够编码用户输入控制,导致允许未
CVSS Information
N/A
Vulnerability Type
N/A