Medium severity5.5NVD Advisory· Published Jul 22, 2021· Updated Jun 17, 2026
CVE-2020-7389
CVE-2020-7389
Description
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
Affected products
4- Sage/X3v5Range: V9
Patches
Vulnerability mechanics
References
2- www.rapid7.com/blog/post/2021/07/07/cve-2020-7387-7390-multiple-sage-x3-vulnerabilities/nvdExploitThird Party Advisory
- rapid7.com/blog/post/2021/07/07/sage-x3-multiple-vulnerabilities-fixednvdBroken Link
News mentions
0No linked articles in our index yet.