PT-2021-20253 · Sap · Sap Contact Center
Published
2021-09-14
·
Updated
2021-09-24
·
CVE-2021-33675
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP Contact Center version 700
Description:
The issue arises from insufficient encoding of user-controlled inputs, leading to a Reflected Cross-Site Scripting (XSS) vulnerability. This can be exploited by an attacker through phishing, allowing the execution of arbitrary code on the victim's browser.
Recommendations:
For SAP Contact Center version 700, ensure proper encoding of user-controlled inputs to prevent XSS attacks. As a temporary workaround, consider implementing additional input validation and sanitization measures to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Contact Center