CVE-2020-7390: Sage X3 Syracuse Persistent XSS in Edit User page

Published Jul 22, 2021
·
Updated

Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions of Sage X3 are unaffected or unsupported by the vendor.

Other sources

Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions of Sage X3 are unaffected or unsupported by the vendor.

Affected Software

2 affected components
Sage Syracuse>=12.0<12.10.0
Sage X3=12.0

Event History

Jul 22, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2020-7390?

CVE-2020-7390 is a stored Cross-Site Scripting (XSS) vulnerability in the Sage X3 web application.

2

How does CVE-2020-7390 affect Sage X3?

CVE-2020-7390 allows an authenticated user to inject XSS strings into the "First Name," "Last Name," and "Email Address" fields on the 'Edit' page of the User Profile in Sage X3.

3

What is the severity of CVE-2020-7390?

CVE-2020-7390 has a severity score of 5.4, which is considered medium.

4

Which versions of Sage X3 are affected by CVE-2020-7390?

On-premises versions of Sage X3 up to and including Version 12.10.0 are affected by CVE-2020-7390.

5

How can I fix CVE-2020-7390 in Sage X3?

To fix CVE-2020-7390, it is recommended to apply the available updates for on-premises versions of Sage X3, specifically Version 12 (components shipped with Syracuse).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203