PT-2024-33169 · Sage · Sage 1000
Published
2024-10-20
·
Updated
2025-06-27
·
CVE-2024-48646
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Sage 1000 version 7.0.0
Description
The issue allows authorized users to upload files without proper validation, which can be exploited by uploading malicious files, such as HTML, scripts, or other executable content. This could lead to the execution of these files on the server and result in further system compromise.
Recommendations
For Sage 1000 version 7.0.0, consider restricting file uploads to only authorized and validated files to prevent potential exploitation. As a temporary workaround, restrict access to the file upload feature until a proper validation mechanism is implemented.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sage 1000