CVE-2020-6313 is a Stored Cross-Site Scripting (XSS) vulnerability affecting SAP NetWeaver Application Server JAVA (XML Forms) versions 7.30, 7.31, 7.40, and 7.50. An authenticated user with specific roles can inject and store malicious content due to insufficient input encoding. When a victim accesses this content, JavaScript can execute, leading to malicious actions. Rated Medium severity with a CVSS score of 6.5, this vulnerability requires network access and low privileges, but no user interaction for successful exploitation (AV:N/AC:L/PR:L/UI:N). The primary impact is high integrity compromise (I:H), with no confidentiality or availability impact. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.30CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:* | ||
7.31CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:* | ||
7.40CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:* | ||
7.50CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.