PT-2026-70043 · Sap · Sapui5
CVE-2026-66771
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAPUI5 (affected versions not specified)
Description
SAPUI5 contains a Cross Site Scripting (XSS) flaw where a key user with content adaptation privileges can inject malicious script content into persisted application changes. This script executes in the browser session of any user who subsequently opens the adapted application. This could allow an attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, impacting confidentiality and integrity.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sapui5