File Disclosure Vulnerability in Sage 1000 by Sage Group
CVE-2024-48647
7.2HIGH
What is CVE-2024-48647?
A file disclosure vulnerability exists in Sage 1000 v7.0.0 that enables remote attackers to exploit the URL parameter in HTTP requests. By targeting this vulnerability, attackers can retrieve arbitrary files from the server's file system. The exposure of sensitive information such as configuration files and credentials poses a significant risk, potentially leading to further unauthorized access and compromise of the server’s integrity. It is essential for users of Sage 1000 to assess their security configurations and apply necessary updates to mitigate this risk.
