VYPR

X3

by Sage

CVEs (3)

  • CVE-2023-31867HigJun 22, 2023
    risk 0.47cvss 7.2epss 0.01

    Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.

  • CVE-2020-7389MedJul 22, 2021
    risk 0.36cvss 5.5epss 0.02

    Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

  • CVE-2023-31868MedJun 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when…