PT-2021-12651 · Sage · Sage X3 System

Aaron Herndon

+7

·

Published

2021-07-22

·

Updated

2022-07-15

·

CVE-2020-7389

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Sage X3 System (affected versions not specified)
Description: The issue allows an authenticated user with developer access to inject OS commands via the CHAINE variable used by the web application. It is noted that this developer configuration should not be deployed in production.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7389

Affected Products

Sage X3 System