Back to Database
Status published
Unknown
CVE-2022-34324
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow...
Vulnerability Description
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-34324
Credits & Attribution
No credits recorded in the NVD database.
More from sage
View All →CVE-2022-41400
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key...
Unknown
0
CVE-2022-41399
The optional Web Screens feature for Sage 300 through version...
Unknown
0
CVE-2022-41398
The optional Global Search feature for Sage 300 through version...
Unknown
0
CVE-2022-41397
The optional Web Screens and Global Search features for Sage...
Unknown
0
CVE-2022-38583
On versions of Sage 300 2017 - 2022 (6.4.x -...
Unknown
0
Affected Vendor
sage
View all reports →Affected Software
sage xrt business exchange
Vulnerable Versions:
12.4.302
Timeline
Official Publish:
January 1st, 2023
Last Modified:
April 11th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.