PT-2021-12651 · Sage · Sage X3 System
Aaron Herndon
+7
·
Published
2021-07-22
·
Updated
2022-07-15
·
CVE-2020-7389
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Sage X3 System (affected versions not specified)
Description:
The issue allows an authenticated user with developer access to inject OS commands via the
CHAINE variable used by the web application. It is noted that this developer configuration should not be deployed in production.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sage X3 System