CVE-2020-6278
CVE-2020-6278
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Jul 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading to Stored Cross Site Scripting
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
SAP SE · SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →