An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise.
History

Thu, 31 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Sage
Sage 1000
Weaknesses CWE-434
CPEs cpe:2.3:a:sage:1000:7.0.0:*:*:*:*:*:*:*
Vendors & Products Sage
Sage 1000
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Oct 2024 18:00:00 +0000

Type Values Removed Values Added
Description An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-30T00:00:00

Updated: 2024-10-31T17:33:33.534Z

Reserved: 2024-10-08T00:00:00

Link: CVE-2024-48646

cve-icon Vulnrichment

Updated: 2024-10-31T17:33:06.114Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-30T18:15:07.640

Modified: 2024-11-01T12:57:03.417

Link: CVE-2024-48646

cve-icon Redhat

No data.