CVE-2025-1886

HIGH

Sage 200 Spain <2025.35.000 - Info Disclosure

Title source: llm
STIX 2.1

Description

Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials.

Scores

CVSS v4 7.1
EPSS 0.0016
EPSS Percentile 36.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (1)
Sage/Sage 200 Spain 2025.35.000
Published Mar 07, 2025
Tracked Since Feb 18, 2026