An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.