Vulnerabilities (CVE)

Filtered by vendor Sage
Filtered by product X3
Angry Yack Logo
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-31868 1 Sage 1 X3 2024-11-21 N/A 5.4 MEDIUM
Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by the application and executed by the web browser of the user viewing the web page. Several injection points have been identified on the application. Th ...

Show More

CVE-2023-31867 1 Sage 1 X3 2024-11-21 N/A 7.2 HIGH
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
CVE-2020-7390 1 Sage 2 Syracuse, X3 2024-11-21 3.5 LOW 4.6 MEDIUM
Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions of Sage X3 are unaffected or unsupported by the vendor.
CVE-2020-7389 1 Sage 2 Syracuse, X3 2024-11-21 9.0 HIGH 5.5 MEDIUM
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
CVE-2020-7388 1 Sage 3 Adxadmin, X3, X3 Hr \& Payroll 2024-11-21 7.5 HIGH 10.0 CRITICAL
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the installation path, that information can be learned by exploiting CVE-2020-7387. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions of Sage X3 including Version 9 (components shipped with Syracuse 9.22.7.2 and later), Sa ...

Show More

CVE-2020-7387 1 Sage 3 Adxadmin, X3, X3 Hr \& Payroll 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. Note that this vulnerability can be combined with CVE-2020-7388 to achieve full RCE. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions of Sage X3 Version 9 (components shipped with Syracuse 9.22.7.2 and later), Sage X3 HR & Payroll Version 9 (those components that ship with Syrac ...

Show More