Sage DPW
cpe:2.3:a:sagedpw:sage_dpw:*:*:*:*:*:*:*
- < 2025_06_004
- < 2021_06_004
A vulnerability in Sage DPW version 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, which is disabled by default and not available in Sage DPW Cloud. The vulnerability exposes sensitive information such as database hashes and table names. This issue arises only in non-default, on-premise installations where the Database Monitor was manually enabled.
Exploitation of this vulnerability could lead to unauthorized access to sensitive database information, including user data such as email addresses, password hashes, salts, and metadata.
Users can update to Sage DPW version 2025_06_004, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.