2 results (0.005 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection. • http://sage.com https://github.com/Digitemis/Advisory/blob/main/CVE-2023-31867.txt • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by the application and executed by the web browser of the user viewing the web page. Several injection points have been identified on the application. • http://sage.com https://github.com/Digitemis/Advisory/blob/main/CVE-2023-31868.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •