Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23938 | An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request. |
Wed, 01 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sagedpw
Sagedpw sage Dpw |
|
| CPEs | cpe:2.3:a:sagedpw:sage_dpw:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sagedpw
Sagedpw sage Dpw |
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sage
Sage dpw |
|
| Vendors & Products |
Sage
Sage dpw |
Thu, 07 Aug 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Insecure Direct Object Reference (IDOR) in Sage DPW v2024.12.003 allows unauthorized attackers to access internal forms via sending a crafted GET request. This is fixed in Halbjahresversion 2024_12_004. | An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request. |
Thu, 07 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
ssvc
|
Thu, 07 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Insecure Direct Object Reference (IDOR) in Sage DPW v2024.12.003 allows unauthorized attackers to access internal forms via sending a crafted GET request. This is fixed in Halbjahresversion 2024_12_004. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-07T19:14:17.143Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51533
Updated: 2025-08-07T19:07:46.876Z
Status : Analyzed
Published: 2025-08-07T19:15:28.813
Modified: 2025-10-01T20:36:15.793
Link: CVE-2025-51533
No data.
OpenCVE Enrichment
Updated: 2025-08-12T12:05:43Z
EUVD