CVE-2025-51533
- EPSS 0.06%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 01.10.2025 20:36:15
An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.
CVE-2025-51532
- EPSS 0.06%
- Veröffentlicht 06.08.2025 00:00:00
- Zuletzt bearbeitet 01.10.2025 20:38:28
Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.
CVE-2025-51531
- EPSS 0.04%
- Veröffentlicht 06.08.2025 00:00:00
- Zuletzt bearbeitet 01.10.2025 20:38:41
A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser via injecting a crafted payload into the tabfields parameter at /dpw/script...
CVE-2024-56883
- EPSS 0.65%
- Veröffentlicht 18.02.2025 18:15:27
- Zuletzt bearbeitet 25.09.2025 13:27:35
Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for othe...
CVE-2024-56882
- EPSS 0.06%
- Veröffentlicht 18.02.2025 18:15:26
- Zuletzt bearbeitet 01.10.2025 17:42:56
Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the Kurstitel and Kurzinfo input fields. The injected payload is executed for ea...
CVE-2020-26583
- EPSS 0.78%
- Veröffentlicht 16.10.2020 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:20:07
An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses claiming functionality. However, to view the file, authentication is required. By exploiting this vuln...
CVE-2020-26584
- EPSS 0.45%
- Veröffentlicht 16.10.2020 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:20:07
An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog is vulnerable to Reflected XSS. If the attacker can lure a user into clicking a crafted link, he can execute arbitrary JavaScript...