High severity8.8NVD Advisory· Published Jan 1, 2023· Updated Jun 17, 2026
CVE-2022-34324
CVE-2022-34324
Description
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History.
Affected products
3- cpe:2.3:a:sage:sage_xrt_business_exchange:12.4.302:*:*:*:*:*:*:*
- Sage/XRT Business Exchangedescription
Patches
Vulnerability mechanics
References
1- www.synacktiv.com/sites/default/files/2022-12/sage_xrt_multiple_sqli_1.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.