CVE-2023-30743
HIGHSAPUI5 - Cross-Site Scripting via sap.m.FormattedText Control
Title source: llmDescription
Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’s interaction with the application. Further, in the absence of URL validation by the application, the vulnerability could lead to the attacker reading or modifying user’s information through phishing attack.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory
https://launchpad.support.sap.com/#/notes/3326210
Scores
CVSS v3
7.1
EPSS
0.0017
EPSS Percentile
37.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (6)
sap/sapui5
700
sap/sapui5
750
sap/sapui5
754
sap/sapui5
755
sap/sapui5
756
sap/sapui5
757
Published
May 09, 2023
Tracked Since
Feb 18, 2026