OSV 1.4.0 · unreviewed · 修改于 2021-12-17 08:00
发布时间
2021-12-15 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-15 00:15
源文件
advisories/unreviewed/2021/12/GHSA-3h3c-qxj3-9h67/GHSA-3h3c-qxj3-9h67.json
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data from the victim but will never be able to modify the document and publish these modifications to the server. It impacts the "Quick Prompt" workflow.
该公告没有提供结构化的受影响软件包信息。