CVE-2025-67807: Medium severity Sagedpw Sage Dpw vulnerability
The login mechanism of Sage DPW 202506004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 202106000. On-premise administrators can toggle this behaviour in newer versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67807?
The severity of CVE-2025-67807 is medium, with a CVSS score of 4.7.
How do I fix CVE-2025-67807?
To fix CVE-2025-67807, ensure your Sage DPW software is updated to version 2021_06_000 or later and toggle the account enumeration behavior in the settings.
What does CVE-2025-67807 affect?
CVE-2025-67807 affects the login mechanism of Sage DPW prior to version 2021_06_000, allowing for account enumeration.
Who is at risk from CVE-2025-67807?
On-premise administrators and users of Sage DPW versions prior to 2021_06_000 are at risk from CVE-2025-67807.
What should I do if I am using an affected version of Sage DPW regarding CVE-2025-67807?
If you are using an affected version of Sage DPW, you should upgrade to the latest version and adjust the relevant settings to mitigate the risk.