Page 2 of 20 results (0.019 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

01 Jan 2023 — Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context of other users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Filters and Display model features (OnlineBanking > Web Monitoring > Settings > Filters / Display models). The name of a filter or a display model is interpreted as HTML and can thus embed JavaScript code, which is executed when displayed. This i... • https://www.synacktiv.com/sites/default/files/2022-12/sage_xrt_multiple_xss.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

14 Jul 2022 — In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. However, this directory is writable by unprivileged users because the Sage installer fails to set explicit permissions and therefore inherits weak permissions from the C:\ folder. Because entries in the system-wide PATH variable are included in the search order for DLLs, an attacker could perform DLL search-order hijacking to esca... • https://controlgap.com/blog?tag=insecurity • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

08 Sep 2011 — Cross-site scripting (XSS) vulnerability in the Sage add-on 1.3.10 and earlier for Firefox allows remote attackers to inject arbitrary web script or HTML via a crafted feed, a different vulnerability than CVE-2009-4102. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados en Sage add-on v1.3.10 y anterior para Firefox, permite a atacantes remotos inyectar código de su elección a través de secuencias de comandos web o HTML a través de un feed modificado. Una vulnerabilidad diferente de CV... • http://jvn.jp/en/jp/JVN30221194/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.3EPSS: 1%CPEs: 3EXPL: 0

28 Nov 2009 — Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed. Sage v1.4.3 y anteriores extensiones para Firefox realiza ciertas operaciones con privilegios del chrome, lo que permite a atacantes remotos ejecutar comandos de su elección y realizar ataques ataques de secuencias de comandos a través de la etiqueta descripción de un fee... • http://forums.mozillazine.org/viewtopic.php?f=48&t=1603515&start=0 • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 1%CPEs: 5EXPL: 1

13 Feb 2007 — Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "