6.1
CVSSv3

CVE-2023-27499

Published: 11/04/2023 Updated: 18/04/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the attacker will execute in the victim user's browser. The information from the victim's web browser can either be modified or read and sent to the attacker.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver 7.22ext

sap netweaver application server abap krnl64uc_7.22

sap netweaver application server abap 7.22

sap netweaver application server abap 7.53

sap netweaver application server abap 7.77

sap netweaver application server abap 7.81

sap netweaver application server abap 7.85

sap netweaver application server abap 7.89

sap netweaver application server abap 7.54

sap netweaver application server abap 7.91

sap netweaver application server abap krnl64uc