Sage Group Sage X3是Sage Group公司的一个应用软件。针对成熟企业开发的企业资源规划产品。 Sage X3存在安全漏洞,该 Metasploit 模块利用 Sage X3 AdxSrv 管理协议中的身份验证绕过漏洞,以系统身份对运行可用 AdxAdmin 服务的 Sage X3 服务器执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof of concept exploit code for CVE-2020-7388, an unauthenticated RCE as SYSTEM on Sage X3's AdxDSrv Service | https://github.com/ac3lives/sagex3-cve-2020-7388-poc | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-7389 | 5.5 MEDIUM | Sage X3 Syracuse Missing Authentication for Critical Function in Developer Environment |
| CVE-2020-7387 | 5.3 MEDIUM | Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2020-7390 | 4.6 MEDIUM | Sage X3 Syracuse Persistent XSS in Edit User page |
No comments yet