Overview
The Sage DPW DB Monitor inserted the tabfields parameter into HTML output without proper filtering. A crafted link could therefore execute JavaScript in a user’s browser.
Technical findings
An affected DB Monitor page was available under /dpw/scripts/cgiip.exe/WService=v8pweb/. It copied the request’s tabfields parameter into the response without appropriate HTML encoding.
This made it possible to construct a link that runs script code when opened. Because the page belongs to an administrative module, the privileges of the person opening the link are particularly important.
The public CVE record categorizes the vulnerability as reflected XSS. According to the vendor, the fix was delivered in release 2025_06_000.
Why it matters
A plausible attack involves sending a crafted link to someone with DB Monitor access. If they open it during an active admin session, the script runs within the browser context of that session.
Potential impact
- JavaScript execution in an administrator’s browser through a manipulated parameter.
- Potential risks include session theft, abuse of privileges, redirects and data exfiltration.
Remediation
- Upgrade to Sage DPW 2025_06_000 or later.
- Strictly validate the tabfields parameter and apply context-appropriate encoding whenever it is output.
- Remove DB Monitor components that are no longer needed from production deployments.
- Harden session cookies with HttpOnly and SameSite; use CSP as an additional XSS mitigation.
Affected and fixed versions
Disclosure timeline
- Discovery
Identified during an external penetration test.
- Initial contact
Initiated the disclosure process with Sage.
- Full report
Submitted the coordinated disclosure report to Sage.
- Vendor discussion
Discussed the findings, CVSS ratings and retest approach together.
- Independent CVSS review
CERT.at largely confirmed the original ratings.
- Fix plan
Sage identified 2025_06_000 as the planned target release.
- Fix release
Sage released the fixes.
- Final disclosure announcement
Announced public disclosure and addressed outstanding questions.
- Public Disclosure
The CVE was published publicly.