CVE-2020-6201: XSS
The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Reflected Cross Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6201?
The severity of CVE-2020-6201 is medium with a severity value of 6.1.
Which versions of SAP Commerce (Testweb Extension) are affected by CVE-2020-6201?
The versions 6.6, 6.7, 1808, 1811, 1905 of SAP Commerce (Testweb Extension) are affected by CVE-2020-6201.
What is the impact of CVE-2020-6201 vulnerability?
The vulnerability CVE-2020-6201 allows for Reflected Cross Site Scripting, which can lead to unauthorized script execution in a user's browser.
How can I mitigate the CVE-2020-6201 vulnerability?
To mitigate the CVE-2020-6201 vulnerability, it is recommended to apply the necessary patches and updates provided by SAP.
Where can I find more information about CVE-2020-6201?
You can find more information about CVE-2020-6201 on SAP's official website.