CVEs Blog | G5 Cyber Security

CVE-2020-26835 – SAP NetWeaver AS ABAP, versions – 740, 750, 751, 752, 753, 754 , does not

SAP NetWeaver AS ABAP, versions – 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (XSS) vulnerability.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26835

Reference (s):

Exit mobile version