Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:NSage Syracuse
APPSage9.0 – 9.22.7.2 (bez)11.0 – 11.25.2.6 (bez)12.0 – 12.10.2.8 (bez)Sage X3
APPSage11.012.09.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Command Injection
Powiązane podatności
CVE-2020-7388CRITICAL10.0PL ✓ten sam produkt
Sage X3: Nieuwierzytelniony RCE jako SYSTEM w komponencie AdxDSrv.exe
CVE-2023-31867HIGH7.2ten sam produkt
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
CVE-2023-31868MEDIUM5.4ten sam produkt
Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application ar...
CVE-2020-7387MEDIUM5.3ten sam produkt
Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.ex...
CVE-2020-7390MEDIUM4.6ten sam produkt
Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings th...