CVE-2020-7390: Sage X3 Syracuse Persistent XSS in Edit User page
Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions of Sage X3 are unaffected or unsupported by the vendor.
Other sources
Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions of Sage X3 are unaffected or unsupported by the vendor.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-7390?
CVE-2020-7390 is a stored Cross-Site Scripting (XSS) vulnerability in the Sage X3 web application.
How does CVE-2020-7390 affect Sage X3?
CVE-2020-7390 allows an authenticated user to inject XSS strings into the "First Name," "Last Name," and "Email Address" fields on the 'Edit' page of the User Profile in Sage X3.
What is the severity of CVE-2020-7390?
CVE-2020-7390 has a severity score of 5.4, which is considered medium.
Which versions of Sage X3 are affected by CVE-2020-7390?
On-premises versions of Sage X3 up to and including Version 12.10.0 are affected by CVE-2020-7390.
How can I fix CVE-2020-7390 in Sage X3?
To fix CVE-2020-7390, it is recommended to apply the available updates for on-premises versions of Sage X3, specifically Version 12 (components shipped with Syracuse).