Sage AR Automation
Missing authorization in administrative functions
An improper authorization vulnerability in the Cash Collect API allows authenticated, low-privileged users to gain administrator privileges.
Reported by Jess Parker
Cybersecurity / Vulnerability research
Senior Cybersecurity Engineer
I’m a senior cybersecurity engineer working across security engineering, penetration testing, and vulnerability research. My experience includes network and Active Directory security, supported by hands-on skills in reconnaissance, enumeration, exploitation, privilege escalation, and technical reporting.
Published work
Publicly documented findings, with credits and source records.
Listed from newest to oldest.
Sage AR Automation
An improper authorization vulnerability in the Cash Collect API allows authenticated, low-privileged users to gain administrator privileges.
Reported by Jess Parker
Sage AR Automation
Insufficient tenant-level authorization in the Cash Collect API allows authenticated users to access administrative resources belonging to other tenants.
Reported by Jess Parker
Delinea Cloud Suite
A SQL injection vulnerability allowing argument injection affects Delinea Cloud Suite versions before 25.2 HF1.
Finders: Jess Parker and Radu Enachi
Summaries are based on public CVE records. Severity scores are the assigning authority’s CVSS 4.0 ratings. See the linked records and vendor release notes for authoritative details.