VYPR

SAS application

by Sas

CVEs (1)

  • CVE-2023-4932MedDec 12, 2023
    risk 0.41cvss 6.3epss 0.01

    SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` parameter of the the `/SASStoredProcess/do` endpoint allows arbitrary JavaScript to be executed when specially crafted URL is opened by an authenticated user. The…