PT-2025-6727 · Sage · Sage Dpw

Maximilian Zingerle

+1

·

Published

2025-02-18

·

Updated

2025-02-18

·

CVE-2024-56882

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sage DPW versions prior to 2024 12 000
Description The issue allows low-privileged Sage users with employee role privileges to permanently store JavaScript code in the Kurstitel and Kurzinfo input fields. The injected payload is executed for each authenticated user who views and interacts with the modified data elements. This is a case of Cross Site Scripting (XSS).
Recommendations For versions prior to 2024 12 000, consider disabling the input fields Kurstitel and Kurzinfo to prevent the storage of malicious JavaScript code until a patch is available. Restrict access to these fields for low-privileged users with employee role privileges to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56882

Affected Products

Sage Dpw