Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the Sage team in version 2025.35.000.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6250 | Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials. |
Fri, 07 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Mar 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials. | |
| Title | Pass-Back vulnerability in Sage 200 Spain | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-07T13:32:27.997Z
Reserved: 2025-03-03T13:11:17.476Z
Link: CVE-2025-1886
Updated: 2025-03-07T13:32:22.370Z
Status : Deferred
Published: 2025-03-07T11:15:15.843
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-1886
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:24Z
EUVD