Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-63620
HistoryMay 23, 2022 - 12:00 a.m.

SAP Cloud Connector Cross-Site Scripting Vulnerability

2022-05-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.001 Low

EPSS

Percentile

22.9%

A cross-site scripting vulnerability exists in SAP Cloud Connector version 2.0, which stems from a program that does not adequately encode user-controlled input and could be exploited by an attacker with administrator privileges to store malicious code in the database An attacker with administrator privileges could store malicious code in the database and execute it in the application when accessed, resulting in a stored cross-site scripting attack.

CPENameOperatorVersion
sap cloud connectoreq2.0

0.001 Low

EPSS

Percentile

22.9%

Related for CNVD-2022-63620