CVE-2025-51531: XSS
A reflected cross-site scripting (XSS) vulnerability in Sage DPW 202412004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser via injecting a crafted payload into the tabfields parameter at /dpw/scripts/cgiip.exe/WService. The vendor has stated that the issue is fixed in 202506000, released in June 2025.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51531?
CVE-2025-51531 is classified as a reflected cross-site scripting (XSS) vulnerability which can allow attackers to execute malicious scripts in the user's browser.
How do I fix CVE-2025-51531?
To fix CVE-2025-51531, upgrade Sage DPW to a version beyond 2024.12.003 to eliminate the vulnerability.
What versions are affected by CVE-2025-51531?
CVE-2025-51531 affects Sage DPW version 2024.12.003 and earlier versions.
What impact does CVE-2025-51531 have on users?
CVE-2025-51531 allows attackers to execute arbitrary JavaScript in the context of a victim's browser, potentially leading to data theft or session hijacking.
Is CVE-2025-51531 a zero-day vulnerability?
CVE-2025-51531 is not classified as a zero-day vulnerability as it has been publicly disclosed and a fix is available.