Due to insufficient encoding of user... CVE-2023-0021

- AV AC AU C I A
发布: 2023-03-14
修订: 2023-11-07

Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.

0%
暂无可用Exp或PoC
当前有6条受影响产品信息