PT-2023-22947 · Sap · Sapui5
Published
2023-05-09
·
Updated
2023-06-15
·
CVE-2023-30743
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SAPUI5 versions SAP UI 750, SAP UI 754, SAP UI 755, SAP UI 756, SAP UI 757, UI 700 200
Description
The issue arises from improper neutralization of input in SAPUI5, allowing the injection of untrusted CSS through the sap.m.FormattedText SAPUI5 control. This can block user interaction with the application. Additionally, the lack of URL validation by the application could enable an attacker to read or modify user information through a phishing attack.
Recommendations
For SAPUI5 versions SAP UI 750, SAP UI 754, SAP UI 755, SAP UI 756, SAP UI 757, UI 700 200, consider disabling the sap.m.FormattedText SAPUI5 control until a patch is available to prevent the injection of untrusted CSS.
Restrict access to the vulnerable SAPUI5 control to minimize the risk of exploitation.
Avoid using the sap.m.FormattedText control in applications where URL validation is not properly implemented until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sapui5