CVE-2025-1886
Severity CVSS v4.0:
HIGH
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
07/03/2025
Last modified:
07/03/2025
Description
Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH