ZeroHour

CVE-2020-7389

PoC
CVSS 3.1
7.2 high
EPSS
2%p80
Published
()
Modified
Description

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

Vendors
sage
Products
syracuse
Weakness
CWE-306, CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news