CVE-2023-42479
Published Dec 12, 2023An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scripting request to the Biller Di…
Vendor/product archive
2 CVEs tagged to sap / biller_direct — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scripting request to the Biller Di…
SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect t…