Multiple XSS Vulnerabilities in Sage XRT Business Exchange
CVE-2022-34323

5.4MEDIUM

Key Information:

Vendor

Sage

Vendor
CVE Published:
1 January 2023

What is CVE-2022-34323?

Sage XRT Business Exchange 12.4.302 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow authenticated attackers to execute arbitrary JavaScript in the context of other users' browsers. Specifically, the issues are found within the Filters and Display model settings, as well as the Notification alert configurations, where user-provided input for filter or alert names is rendered as HTML. This flaw permits attackers to inject malicious scripts. Additionally, a self-XSS vulnerability exists in the file download feature, which improperly embeds user input into JavaScript without adequate sanitization, potentially compromising user data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.