Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: rapid7
Published: 2021-07-22T18:27:15.586124Z
Updated: 2024-09-16T16:53:13.741Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7389
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-07-22T19:15:08.517
Modified: 2024-11-21T05:37:09.920
Link: CVE-2020-7389
Redhat
No data.