CVE-2022-34324

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
01/01/2023
Last modified:
11/04/2025

Description

Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sage:sage_xrt_business_exchange:12.4.302:*:*:*:*:*:*:*