Junglewise Threat Intelligence

CVE-2025-67805: A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor featur

CVE-2025-67805 · Severity: medium · CVSS 5.9 · Published 2026-04-01

Executive brief

Sage DPW is a human resources and payroll software suite used by organizations to manage employee data and financial records. A security flaw in the Database Monitor feature could allow unauthorized individuals to access sensitive diagnostic information, including password hashes and database table names. This issue only affects on-premise installations where this specific monitoring feature was manually enabled, and it does not impact the Sage DPW Cloud service.

Technical details

An information disclosure vulnerability exists in the Database Monitor module of Sage DPW due to missing authentication for critical diagnostic endpoints. The vulnerability is located within the `/scripts/cgiip.exe/WService=dpw_mand/a-905x.r` endpoints. An unauthenticated remote attacker can exploit this to retrieve sensitive data including emails, password hashes, salts, and database table names. This vulnerability only manifests in non-default, on-premise configurations where the Database Monitor has been manually enabled; it is disabled by default and unavailable in Sage DPW Cloud. The vendor addressed this by forcibly disabling the feature in version 2025_06_003 and providing a formal fix in 2025_06_004.

Affected products

  • Sage Sage DPW Prior to 2025_06_004

Timeline

  • 2025-06-03: patched: Feature forcibly disabled in version 2025_06_003
  • 2026-03-24: disclosed: Vulnerability details shared via public advisory
  • 2026-04-01: advisory: CVE-2025-67805 published

References

Related threats