VYPR

SAP GUI for HTML

by SAP

CVEs (2)

  • CVE-2023-27499Apr 11, 2023
    risk 0.00cvss epss 0.00

    SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a…

  • CVE-2022-39799Sep 13, 2022
    risk 0.00cvss epss 0.00

    An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.