Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28515 | Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T16:53:13.741Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7389
No data.
Status : Modified
Published: 2021-07-22T19:15:08.517
Modified: 2024-11-21T05:37:09.920
Link: CVE-2020-7389
No data.
OpenCVE Enrichment
No data.
EUVD