Sagedpw

Sage Dpw

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 07.08.2025 00:00:00
  • Zuletzt bearbeitet 01.10.2025 20:36:15

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 06.08.2025 00:00:00
  • Zuletzt bearbeitet 01.10.2025 20:38:28

Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 06.08.2025 00:00:00
  • Zuletzt bearbeitet 01.10.2025 20:38:41

A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser via injecting a crafted payload into the tabfields parameter at /dpw/script...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 18.02.2025 18:15:27
  • Zuletzt bearbeitet 25.09.2025 13:27:35

Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for othe...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 18.02.2025 18:15:26
  • Zuletzt bearbeitet 01.10.2025 17:42:56

Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the Kurstitel and Kurzinfo input fields. The injected payload is executed for ea...

  • EPSS 0.78%
  • Veröffentlicht 16.10.2020 06:15:12
  • Zuletzt bearbeitet 21.11.2024 05:20:07

An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses claiming functionality. However, to view the file, authentication is required. By exploiting this vuln...

  • EPSS 0.45%
  • Veröffentlicht 16.10.2020 06:15:12
  • Zuletzt bearbeitet 21.11.2024 05:20:07

An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog is vulnerable to Reflected XSS. If the attacker can lure a user into clicking a crafted link, he can execute arbitrary JavaScript...