File Disclosure Vulnerability in Sage 1000 by Sage Group
CVE-2024-48647

7.2HIGH

Key Information:

Vendor

Sage Group

Status
Vendor
CVE Published:
30 October 2024

What is CVE-2024-48647?

A file disclosure vulnerability exists in Sage 1000 v7.0.0 that enables remote attackers to exploit the URL parameter in HTTP requests. By targeting this vulnerability, attackers can retrieve arbitrary files from the server's file system. The exposure of sensitive information such as configuration files and credentials poses a significant risk, potentially leading to further unauthorized access and compromise of the server’s integrity. It is essential for users of Sage 1000 to assess their security configurations and apply necessary updates to mitigate this risk.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.