GHSA-7c49-j52h-hjx4
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file name of the background image resulting in Stored Cross-Site Scripting.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 25, 2025 8:46 PM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.