Impact
A path‑traversal flaw exists in the custom logo upload of Sage Employee Self Service. The application fails to validate the file path submitted by users, enabling attackers to embed directory‑traversal sequences—including encoded forms—to reference files outside the intended directory. If an attacker knows the names of legitimate files, the system will serve the requested resource, potentially exposing configuration, environment, asset and log files.
Affected Systems
The vulnerability affects Sage Employee Self Service by the vendor Sage. The product, Sage Employee Self Service, is susceptible in all versions that have not applied Sage’s remediation. No specific patched versions are mentioned, so any installation lacking the vendor’s fix remains at risk.
Risk and Exploitability
The CVSS score of 5.9 denotes moderate severity; the EPSS is not available and the issue is not listed in the CISA KEV catalog, signifying a potentially non‑negligible risk of exploitation. Attack requires only knowledge of a valid file name and path, not elevated privileges, meaning local or network attackers with access to the web application could use the flaw to read sensitive files and obtain information that may aid further attacks.
OpenCVE Enrichment