Reflected Cross-Site Scripting Vulnerability in Sage 1000 by Sage Software
CVE-2024-48648
6.1MEDIUM
What is CVE-2024-48648?
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Sage 1000 version 7.0.0 that enables attackers to inject harmful scripts through URLs. If successfully exploited, these scripts can be executed in the context of the user’s browser, compromising sensitive data and potentially leading to unauthorized actions on behalf of the user. The vulnerability arises due to insufficient sanitization and encoding of the user input processed by the server, allowing the injection to be reflected back in the server’s response.
