CVE-2025-51533: Medium severity Sage DPW vulnerability
Published Aug 7, 2025
·Updated
An Insecure Direct Object Reference (IDOR) in Sage DPW v202412004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.
Affected Software
2 affected components
Sage DPW<=2024_12_004
Sagedpw Sage Dpw<2025_06_000
Event History
Aug 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51533?
CVE-2025-51533 has a medium severity rating due to the potential for unauthorized access to sensitive internal forms.
2
How do I fix CVE-2025-51533?
To fix CVE-2025-51533, upgrade Sage DPW to version 2024_12_004 or later.
3
What type of vulnerability is CVE-2025-51533?
CVE-2025-51533 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
4
What could an attacker do with CVE-2025-51533?
An attacker could exploit CVE-2025-51533 to access internal forms without proper authorization.
5
Which versions of Sage DPW are affected by CVE-2025-51533?
CVE-2025-51533 affects all versions of Sage DPW prior to 2024_12_004.