VYPR
Medium severity6.1NVD Advisory· Published Sep 14, 2021· Updated Jun 17, 2026

CVE-2021-33673

CVE-2021-33673

Description

Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an attacker to exploit a Stored Cross-Site Scripting (XSS) vulnerability when a user browses through the employee directory and to execute arbitrary code on the victim's browser. Due to the usage of ActiveX in the application, the attacker can further execute operating system level commands.

Affected products

3
  • SAP/Contact Centerllm-create2 versions
    700+ 1 more
    • (no CPE)range: 700
    • cpe:2.3:a:sap:contact_center:700:*:*:*:*:*:*:*
  • SAP SE/SAP Contact Centerv5
    Range: < 700

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.