CVE-2021-33675
- EPSS 0.3%
- Veröffentlicht 14.09.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 06:09:20
Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability through phishing and to execute arbitrary code on...
CVE-2021-33672
- EPSS 0.27%
- Veröffentlicht 14.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:09:19
Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to...
CVE-2021-33673
- EPSS 0.33%
- Veröffentlicht 14.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:09:20
Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an attacker to exploit a Stored Cross-Site Scripting (XSS) vulnerability when a user browses through the ...
CVE-2021-33674
- EPSS 0.27%
- Veröffentlicht 14.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:09:20
Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability when creating a new email and to execute arbitrar...