VYPR

Contact Center

by SAP

CVEs (4)

  • CVE-2021-33672CriSep 14, 2021
    risk 0.62cvss 9.6epss 0.01

    Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to the usage of ActiveX in the…

  • CVE-2021-33675MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability through phishing and to execute arbitrary code on the victim's browser.

  • CVE-2021-33674MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability when creating a new email and to execute arbitrary code on the victim's…

  • CVE-2021-33673MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an attacker to exploit a Stored Cross-Site Scripting (XSS) vulnerability when a user browses through the employee directory and to…