> [Suggested description] > SAPUI5 1.0.0 is vulnerable to Content Spoofing in multiples parameters. > > ------------------------------------------ > > [Additional Information] > https://imgur.com/a/EUf4KN3 > > ------------------------------------------ > > [VulnerabilityType Other] > Content Spoofing > > ------------------------------------------ > > [Vendor of Product] > SAP > > ------------------------------------------ > > [Affected Product Code Base] > SAPUI5 - 1.0.0 > > ------------------------------------------ > > [Affected Component] > SAPUI5 1.0.0 > > PoC: > https://sapmobile.target.com/sap/opu/odata/UI2/INTEROP/PersContainers(category='P',id='flp.settings.FlpSettings')?$expand=PersContainerItemsu1kpa_HACKED_&sap-cache-id=D49C673A8D0D275477C7CD1FBFA3EE31 > > ------------------------------------------ > > [Attack Type] > Remote > > ------------------------------------------ > > [Attack Vectors] > https://imgur.com/a/EUf4KN3 > > ------------------------------------------ > > [Reference] > https://capec.mitre.org/data/definitions/148.html > > ------------------------------------------ > > [Discoverer] > Offensive0Labs - Rafael Fontes Souza