CNNVD-202508-705 Information

CNNVD ID

CNNVD-202508-705

CVE-2025-51533

  • CNNVD Published: 2025-08-07

Description (Chinese)

Sage DPW是英国Sage公司的一个人力资源系统。 Sage DPW 2024_12_004及之前版本存在安全漏洞,该漏洞源于不安全的直接对象引用,可能导致未授权访问。

Description (English)

Sage DPW is a human resources system of Sage UK. There is a security loophole in Sage DPW 2024 12 004 and earlier versions, which stems from unsafe direct reference and may lead to unauthorized access.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Sage

Published

2025-08-07

Last Modified

2026-02-24

References

https://www.sec4you-pentest.com/schwachstelle/sage-dpw-vorhersehbare-url-ids-ermoeglichen-unautorisierten-zugriff-auf-interne-formulare/ https://www.sec4you-pentest.com/schwachstellen

Patch

https://www.sagedpw.at/

Share on: