PT-2024-33169 · Sage · Sage 1000

Published

2024-10-20

·

Updated

2025-06-27

·

CVE-2024-48646

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sage 1000 version 7.0.0
Description The issue allows authorized users to upload files without proper validation, which can be exploited by uploading malicious files, such as HTML, scripts, or other executable content. This could lead to the execution of these files on the server and result in further system compromise.
Recommendations For Sage 1000 version 7.0.0, consider restricting file uploads to only authorized and validated files to prevent potential exploitation. As a temporary workaround, restrict access to the file upload feature until a proper validation mechanism is implemented.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-48646

Affected Products

Sage 1000