Security Advisory

CVE-2025-51533Predictable URL IDs expose internal forms without authorization

Sage DPW v8 · Sage GmbH

CVE published 7 Aug 2025 · discovered 16 Apr 2025

Overview

Internal Sage DPW forms could be discovered systematically using predictable resource IDs. This became a security issue when the discovered pages lacked effective server-side authentication or authorization checks.

Technical findings

Testing revealed a repeating naming convention for HTML resources. Automating requests against that pattern exposed internal forms and search features that were not linked from normal navigation.

Predictable URLs alone are not a vulnerability. The real problem arises when a discovered resource does not require server-side authorization. Hidden paths are not access controls.

In testing, enumeration led to additional findings, including the unprotected DB Monitor and an XSS vector in the same administrative area. It illustrates how smaller weaknesses can combine into an attack chain.

Why it matters

An unauthenticated attacker can automatically probe plausible resource identifiers. Each resulting page must then be assessed individually. This is how simple enumeration can escalate into actual access to functionality or data.

Potential impact

  • Predictable IDs can enable automated guessing and enumeration of internal URLs.

Remediation

  • Check authentication and specific permissions on the server for every resource, regardless of whether its URL is publicly linked.
  • Upgrade to vendor-specified release 2025_06_000 or later.
  • Never treat unpredictable identifiers as an authorization mechanism; hard-to-guess IDs can hinder enumeration but cannot replace access checks.
  • Remove obsolete forms and administrative endpoints, or restrict them at the network level.

Affected and fixed versions

Affected<= 2024_12_004
Fixed / vendor-confirmed2025_06_000 (June 2025)

Disclosure timeline

  1. Discovery

    Identified during an external penetration test.

  2. Initial contact

    Initiated the disclosure process with Sage.

  3. Full report

    Submitted the coordinated disclosure report to Sage.

  4. Vendor discussion

    Discussed technical findings, CVSS and the retest procedure together.

  5. Independent CVSS review

    CERT.at confirmed the original ratings, with a minor adjustment to one finding.

  6. Fix plan

    Sage identified 2025_06_000 as the planned target release.

  7. Fix release

    Sage released the fixes; the researcher was not initially notified.

  8. CVE IDs shared with vendor

    Shared reserved CVE IDs with the vendor and requested clarification of the affected and fixed versions again.

  9. Final disclosure announcement

    Announced public disclosure and followed up on outstanding remediation questions.

  10. Public Disclosure

    The CVE was published publicly.

References

Related Sage DPW research