CVE-2025-1886: Pass-Back vulnerability in Sage 200 Spain
Published Mar 7, 2025
·Updated
Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials.
Affected Software
1 affected component
Sage 200 Spain<2025.35.000
Remediation
Information
The vulnerability has been fixed by the Sage team in version 2025.35.000.
Event History
Mar 7, 2025
CVE Published
via MITRE·10:55 AM
Data Sourced
via MITRE·10:55 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1886?
CVE-2025-1886 is considered a high-severity vulnerability due to the potential exposure of sensitive SMTP credentials.
2
How do I fix CVE-2025-1886?
To fix CVE-2025-1886, upgrade Sage 200 Spain to version 2025.35.000 or later.
3
Who is affected by CVE-2025-1886?
CVE-2025-1886 affects users of Sage 200 Spain versions prior to 2025.35.000.
4
What type of attack can exploit CVE-2025-1886?
An authenticated attacker with administrator privileges can exploit CVE-2025-1886 to discover stored SMTP credentials.
5
Is there a workaround for CVE-2025-1886?
There is no documented workaround for CVE-2025-1886; the recommended solution is to upgrade the software.