CVE-2020-6200: XSS
The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6200?
CVE-2020-6200 is a vulnerability in the SAP Commerce (SmartEdit Extension) versions 6.6, 6.7, 1808, and 1811, which allows for client-side angularjs template injection, a variant of Cross-Site Scripting (XSS).
What is the severity of CVE-2020-6200?
The severity of CVE-2020-6200 is medium with a CVSS score of 5.4.
What software versions are affected by CVE-2020-6200?
The SAP Commerce Cloud versions 6.6, 6.7, 1808, and 1811 are affected by CVE-2020-6200.
How can I fix CVE-2020-6200?
To fix CVE-2020-6200, it is recommended to apply the necessary patches provided by SAP. Refer to the SAP Support Portal for detailed instructions.
Where can I find more information about CVE-2020-6200?
You can find more information about CVE-2020-6200 on the SAP Support Portal and the SAP Community Wiki.