Insecure Direct Object Reference in Sage DPW by Sage
CVE-2025-51533

5.3MEDIUM

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-51533?

A vulnerability in Sage DPW versions prior to v2024_12_005 allows unauthorized attackers to manipulate URL parameters, gaining access to internal forms that should be restricted. This IDOR weakness can be exploited through crafted GET requests, potentially exposing sensitive information and compromising the security of affected systems.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.