Overview
Internal Sage DPW forms could be discovered systematically using predictable resource IDs. This became a security issue when the discovered pages lacked effective server-side authentication or authorization checks.
Technical findings
Testing revealed a repeating naming convention for HTML resources. Automating requests against that pattern exposed internal forms and search features that were not linked from normal navigation.
Predictable URLs alone are not a vulnerability. The real problem arises when a discovered resource does not require server-side authorization. Hidden paths are not access controls.
In testing, enumeration led to additional findings, including the unprotected DB Monitor and an XSS vector in the same administrative area. It illustrates how smaller weaknesses can combine into an attack chain.
Why it matters
An unauthenticated attacker can automatically probe plausible resource identifiers. Each resulting page must then be assessed individually. This is how simple enumeration can escalate into actual access to functionality or data.
Potential impact
- Predictable IDs can enable automated guessing and enumeration of internal URLs.
Remediation
- Check authentication and specific permissions on the server for every resource, regardless of whether its URL is publicly linked.
- Upgrade to vendor-specified release 2025_06_000 or later.
- Never treat unpredictable identifiers as an authorization mechanism; hard-to-guess IDs can hinder enumeration but cannot replace access checks.
- Remove obsolete forms and administrative endpoints, or restrict them at the network level.
Affected and fixed versions
Disclosure timeline
- Discovery
Identified during an external penetration test.
- Initial contact
Initiated the disclosure process with Sage.
- Full report
Submitted the coordinated disclosure report to Sage.
- Vendor discussion
Discussed technical findings, CVSS and the retest procedure together.
- Independent CVSS review
CERT.at confirmed the original ratings, with a minor adjustment to one finding.
- Fix plan
Sage identified 2025_06_000 as the planned target release.
- Fix release
Sage released the fixes; the researcher was not initially notified.
- CVE IDs shared with vendor
Shared reserved CVE IDs with the vendor and requested clarification of the affected and fixed versions again.
- Final disclosure announcement
Announced public disclosure and followed up on outstanding remediation questions.
- Public Disclosure
The CVE was published publicly.