Role-based Access Control Flaw in Sage 300 by Sage Software
CVE-2023-29927
4.3MEDIUM
What is CVE-2023-29927?
Sage 300 suffers from a significant access control vulnerability due to role-based access being enforced only on the client side. This flaw allows low-privileged users, particularly in configurations like 'Windows Peer-to-Peer Network' or 'Client Server Network', to gain unauthorized access to the underlying database. These users can retrieve sensitive SQL connection strings, enabling them to create, update, or delete any company records without adhering to the designed role-based restrictions. Organizations using affected versions of Sage 300 must take immediate action to mitigate this risk and safeguard their data.
