Loading HuntDB...

GHSA-mqmw-59rf-wv9g

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.547.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the attacker will execute in the victim user's browser. The information from the victim's web browser can either be modified or read and sent to the attacker.

Related CVEs

Key Information

GHSA ID
GHSA-mqmw-59rf-wv9g
Published
April 11, 2023 3:31 AM
Last Modified
April 4, 2024 3:23 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 8, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.