Skip to main content

Vendor/product archive

sage / x3 CVEs

Beta · best-effort

6 CVEs tagged to sage / x31 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-31868

Published Jun 22, 2023

Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not ve…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31867

Published Jun 22, 2023

Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7390

Published Jul 22, 2021

Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web a…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-7389

Published Jul 22, 2021

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-7388

Published Jul 22, 2021

Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential val…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-7387

Published Jul 22, 2021

Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. N…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1