Stored XSS Vulnerabilities in Sage Enterprise Intelligence by Sage Group
CVE-2022-34322

9CRITICAL

Key Information:

Vendor

Sage

Vendor
CVE Published:
1 January 2023

What is CVE-2022-34322?

Multiple stored XSS vulnerabilities were identified in Sage Enterprise Intelligence 2021 R1.1 that could allow authenticated attackers to execute malicious JavaScript code within users' browsers. Specifically, vulnerabilities exist in the 'Notify Users About Modification' menu and the notifications feature, enabling an attacker to send harmful notifications that execute code when viewed by users. Additionally, a self-XSS vulnerability in the Favorites tab occurs when folder or favorite names are processed as HTML, allowing embedded JavaScript to run during display. These issues can lead to unauthorized actions taken in the context of the application.

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.