Back to search
CVE-2020-7389
Published: Jul 22, 2021
Modified: Sep 16, 2024
PUBLISHED
CVSS v3.1
5.5
MEDIUM
Description
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
| Vendor | Product | Versions |
|---|---|---|
Sage | X3 | affected V9 - < Syracuse 9.22.7.2affected V11 - < Syracuse 11.25.2.6affected V12 - < Syracuse 12.10.2.8 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now