Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1511316-7)
SAP Support Packages
(SAPK-30027INFINBASIS, SAPK-60020INFINBASIS, SAPK-60210INFINBASIS, SAPK-60309INFINBASIS, SAPK-60409INFINBASIS, SAPK-60504INFINBASIS)
Описание
FIN-CGV-MIC executes certain functions by referencing specific URLs. When malicious user tricks an authenticated user's browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user.
The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim.
The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim.
Как исправить
Ссылки