CVE-2024-48648

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:sage:sage_frp_1000:7.0.0:*:*:*:*:*:*:*

History

27 Jun 2025, 19:49

Type Values Removed Values Added
First Time Sage
Sage sage Frp 1000
CPE cpe:2.3:a:sage:sage_frp_1000:7.0.0:*:*:*:*:*:*:*
References () https://github.com/hx381/Sage-1000-v7.0.0-Exploit/blob/main/README.md - () https://github.com/hx381/Sage-1000-v7.0.0-Exploit/blob/main/README.md - Exploit, Third Party Advisory

30 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-30 18:15

Updated : 2025-06-27 19:49


NVD link : CVE-2024-48648

Mitre link : CVE-2024-48648


JSON object : View

Products Affected

sage

  • sage_frp_1000
CWE

No CWE.