GHSA-2gh9-j675-j2ff
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 8, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.