Reflected Cross-Site Scripting Vulnerability in Sage 1000 by Sage Software
CVE-2024-48648

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 October 2024

What is CVE-2024-48648?

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Sage 1000 version 7.0.0 that enables attackers to inject harmful scripts through URLs. If successfully exploited, these scripts can be executed in the context of the user’s browser, compromising sensitive data and potentially leading to unauthorized actions on behalf of the user. The vulnerability arises due to insufficient sanitization and encoding of the user input processed by the server, allowing the injection to be reflected back in the server’s response.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.