ZeroHour

CVE-2024-48648

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p27
Published
()
Modified
Description

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.

Vendors
sage
Products
sage frp 1000
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.