An Insecure Direct Object Reference (IDOR) in Sage DPW v2024.12.003 allows unauthorized attackers to access internal forms via sending a crafted GET request. This is fixed in Halbjahresversion 2024_12_004.
Publication date: Thu, 07 Aug 2025 00:00:00 +0000