PT-2020-16467 · Sage · Sage Dpw

Published

2020-10-16

·

Updated

2020-10-29

·

CVE-2020-26583

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sage DPW versions prior to 2020 06 002
Description The issue allows unauthenticated users to upload JavaScript files via the expenses claiming functionality, although authentication is required to view the file. This enables an attacker to persistently include arbitrary HTML or JavaScript code into the affected web page, potentially changing the site's contents, redirecting users to other sites, or stealing user credentials. Users may also be vulnerable to browser exploits and JavaScript malware.
Recommendations For versions prior to 2020 06 002, update to version 2020 06 002 or later to resolve the issue. As a temporary workaround, consider restricting access to the expenses claiming functionality to prevent unauthenticated users from uploading malicious files.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26583

Affected Products

Sage Dpw