PT-2020-16467 · Sage · Sage Dpw
Published
2020-10-16
·
Updated
2020-10-29
·
CVE-2020-26583
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sage DPW versions prior to 2020 06 002
Description
The issue allows unauthenticated users to upload JavaScript files via the expenses claiming functionality, although authentication is required to view the file. This enables an attacker to persistently include arbitrary HTML or JavaScript code into the affected web page, potentially changing the site's contents, redirecting users to other sites, or stealing user credentials. Users may also be vulnerable to browser exploits and JavaScript malware.
Recommendations
For versions prior to 2020 06 002, update to version 2020 06 002 or later to resolve the issue. As a temporary workaround, consider restricting access to the expenses claiming functionality to prevent unauthenticated users from uploading malicious files.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sage Dpw