CVE-2024-48648: XSS
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48648?
CVE-2024-48648 is classified as a high severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2024-48648?
To mitigate CVE-2024-48648, ensure that proper input validation and output encoding are implemented to sanitize user inputs in URLs.
What software is affected by CVE-2024-48648?
CVE-2024-48648 affects Sage 1000 version 7.0.0.
What type of vulnerability is CVE-2024-48648?
CVE-2024-48648 is a Reflected Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-48648 lead to data theft?
Yes, exploiting CVE-2024-48648 can lead to data theft by executing malicious scripts in the context of the user's session.