CVE-2020-7387 is a pathname disclosure vulnerability affecting Sage X3, Sage X3 HR & Payroll, and Sage AdxAdmin, where a specially crafted network packet can reveal the product's installation directory. Rated Medium with a CVSSv3.1 score of 5.3, this vulnerability has low confidentiality impact on its own but can be combined with CVE-2020-7388 to achieve full remote code execution, significantly increasing its overall risk. Its high EPSS score and FAUCET risk score of 71.0 indicate a notable probability of exploitation. While not in CISA's KEV, it is on the Hot List, and a Metasploit module exists for the combined RCE exploit. There is considerable community discussion and media coverage highlighting the critical nature of the combined vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 93.2.53CPE matchmatch criteria | cpe:2.3:a:sage:adxadmin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.