CVE-2024-48648

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.
Configurations

No configuration.

History

31 Oct 2024, 17:35

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Cross Site Scripting (XSS) Reflejado en Sage 1000 v 7.0.0. Esta vulnerabilidad permite a los atacantes inyectar secuencias de comandos maliciosas en las URL, que el servidor refleja en la respuesta sin la codificación ni la desinfección adecuadas.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

30 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-30 18:15

Updated : 2024-11-01 12:57


NVD link : CVE-2024-48648

Mitre link : CVE-2024-48648

CVE.ORG link : CVE-2024-48648


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')