Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6250 Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials.
Fixes

Solution

The vulnerability has been fixed by the Sage team in version 2025.35.000.


Workaround

No workaround given by the vendor.

History

Fri, 07 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials.
Title Pass-Back vulnerability in Sage 200 Spain
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-03-07T13:32:27.997Z

Reserved: 2025-03-03T13:11:17.476Z

Link: CVE-2025-1886

cve-icon Vulnrichment

Updated: 2025-03-07T13:32:22.370Z

cve-icon NVD

Status : Received

Published: 2025-03-07T11:15:15.843

Modified: 2025-03-07T11:15:15.843

Link: CVE-2025-1886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T15:26:24Z