Security Advisory

CVE-2025-51531XSS in the DB Monitor (tabfields)

Sage DPW v8 · Sage GmbH

CVE published 6 Aug 2025 · discovered 16 Apr 2025

Overview

The Sage DPW DB Monitor inserted the tabfields parameter into HTML output without proper filtering. A crafted link could therefore execute JavaScript in a user’s browser.

Technical findings

An affected DB Monitor page was available under /dpw/scripts/cgiip.exe/WService=v8pweb/. It copied the request’s tabfields parameter into the response without appropriate HTML encoding.

This made it possible to construct a link that runs script code when opened. Because the page belongs to an administrative module, the privileges of the person opening the link are particularly important.

The public CVE record categorizes the vulnerability as reflected XSS. According to the vendor, the fix was delivered in release 2025_06_000.

Why it matters

A plausible attack involves sending a crafted link to someone with DB Monitor access. If they open it during an active admin session, the script runs within the browser context of that session.

Potential impact

  • JavaScript execution in an administrator’s browser through a manipulated parameter.
  • Potential risks include session theft, abuse of privileges, redirects and data exfiltration.

Remediation

  • Upgrade to Sage DPW 2025_06_000 or later.
  • Strictly validate the tabfields parameter and apply context-appropriate encoding whenever it is output.
  • Remove DB Monitor components that are no longer needed from production deployments.
  • Harden session cookies with HttpOnly and SameSite; use CSP as an additional XSS mitigation.

Affected and fixed versions

Affected<= 2024_12_004
Fixed / vendor-confirmed2025_06_000 (June 2025)

Disclosure timeline

  1. Discovery

    Identified during an external penetration test.

  2. Initial contact

    Initiated the disclosure process with Sage.

  3. Full report

    Submitted the coordinated disclosure report to Sage.

  4. Vendor discussion

    Discussed the findings, CVSS ratings and retest approach together.

  5. Independent CVSS review

    CERT.at largely confirmed the original ratings.

  6. Fix plan

    Sage identified 2025_06_000 as the planned target release.

  7. Fix release

    Sage released the fixes.

  8. Final disclosure announcement

    Announced public disclosure and addressed outstanding questions.

  9. Public Disclosure

    The CVE was published publicly.

References

Related Sage DPW research