VYPR
Unrated severityNVD Advisory· Published Jul 10, 2019· Updated Aug 4, 2024

CVE-2019-0281

CVE-2019-0281

Description

SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Affected products

4
  • SAP/SAPUI5llm-fuzzy
    Range: <1.38.39, <1.44.39, <1.52.25, <1.60.6, <1.63.0
  • SAP/OpenUI5llm-fuzzy
    Range: <1.38.39, <1.44.39, <1.52.25, <1.60.6, <1.63.0
  • SAP SE/OpenUI5v5
    Range: 1.38.39
  • SAP SE/SAPUI5v5
    Range: 1.38.39

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.