ZeroHour

CVE-2018-2474

CVSS 3.0
6.5 medium
EPSS
<1%p50
Published
()
Modified
Description

SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.

Vendors
sap
Products
fiori
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news