Sage DPW
cpe:2.3:a:sagedpw:sage_dpw:*:*:*:*:*:*:*
- <= 2024_12_004
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in Sage DPW versions through 2024_12_004. This vulnerability allows unauthorized attackers to access internal forms by sending a crafted GET request. The issue arises from predictable URL patterns that can be exploited to crawl internal pages without authentication, potentially leading to unauthorized access to sensitive data and operations.
Exploitation of this vulnerability allows unauthorized access to internal forms and functions, bypassing authentication. This can expose sensitive data and operations, with certain functions inheriting the current application privilege context, potentially leading to unauthorized state-changing actions.
The vulnerability can be reproduced by sending GET requests to URLs with predictable numeric or alphanumeric patterns, such as A-0001.htm to A-9999.htm. This can be done manually or through automated crawling. The accessed pages may require no authentication and can include full or partial functionality, with some internal links leading to additional unauthenticated screens.
Users are advised to update to Sage DPW version 2025_06_000.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.