CVE Feed

    Dashboard / CVE / CVE-2020-7390

    CVE-2020-7390

    Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions of Sage X3 are unaffected or unsupported by the vendor.

    Published:Jul 22, 2021
    Last Modified:Nov 21, 2024
    EPS:Jul 22, 2021
    EPSS Score:0.00328
    CVSS Score:4.6

    Affected Products

    Vendor
    Sage
    Product
    Syracuse
    Vendor
    Sage
    Product
    X3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High