CVE-2023-30743 is a medium-severity vulnerability affecting SAPUI5 versions SAP_UI 750, 754, 755, 756, 757, and UI_700 200. It stems from improper input neutralization in the sap.m.FormattedText control, allowing untrusted CSS injection. This can block user interaction and, if the application lacks URL validation, facilitate phishing attacks to read or modify user information. The vulnerability has a CVSS score of 6.1 (Medium), indicating a network-based attack requiring user interaction, with low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
700CPE matchmatch criteria | cpe:2.3:a:sap:sapui5:700:*:*:*:*:*:*:* | ||
750CPE matchmatch criteria | cpe:2.3:a:sap:sapui5:750:*:*:*:*:*:*:* | ||
754CPE matchmatch criteria | cpe:2.3:a:sap:sapui5:754:*:*:*:*:*:*:* | ||
755CPE matchmatch criteria | cpe:2.3:a:sap:sapui5:755:*:*:*:*:*:*:* | ||
756CPE matchmatch criteria | cpe:2.3:a:sap:sapui5:756:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.