ID | CVE-2021-33703 | ||||||
Sažetak | Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker can craft a malicious link and send it to a victim. A successful attack results in Reflected Cross-Site Scripting (XSS) vulnerability. | ||||||
Reference | |||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:H/Au:N/C:N/I:P/A:N | ||||||
Zadnje važnije ažuriranje | 04-02-2022 - 16:24 | ||||||
Objavljeno | 10-08-2021 - 15:15 |