CVE-2022-34324 describes multiple authenticated SQL injection vulnerabilities in Sage XRT Business Exchange version 12.4.302, specifically within the Add Currencies, Payment Order, and Transfer History functionalities. This high-severity vulnerability (CVSS 8.8) allows a low-privileged attacker to execute arbitrary SQL queries, leading to potential compromise of confidentiality, integrity, and availability of the system. While no public exploits, Metasploit modules, or KEV catalog entries exist, and there is minimal community discussion or media coverage, the vulnerability's nature makes it a significant risk if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.4.302CPE matchmatch criteria | cpe:2.3:a:sage:sage_xrt_business_exchange:12.4.302:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.