X3
by Sage
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-31867 | Hig | 0.47 | 7.2 | 0.01 | Jun 22, 2023 | Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection. | ||
| CVE-2020-7389 | Med | 0.36 | 5.5 | 0.02 | Jul 22, 2021 | Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production. | ||
| CVE-2023-31868 | Med | 0.35 | 5.4 | 0.00 | Jun 22, 2023 | Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when… |
- risk 0.47cvss 7.2epss 0.01
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
- risk 0.36cvss 5.5epss 0.02
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
- risk 0.35cvss 5.4epss 0.00
Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when…