Vulnerability Details CVE-2020-6210
SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.1%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 4.3
Products affected by CVE-2020-6210
-
cpe:2.3:a:sap:fiori_launchpad:753
-
cpe:2.3:a:sap:fiori_launchpad:754