Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-34323

EPSS 0.27% · P51
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-34323

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context of other users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Filters and Display model features (OnlineBanking > Web Monitoring > Settings > Filters / Display models). The name of a filter or a display model is interpreted as HTML and can thus embed JavaScript code, which is executed when displayed. This is a stored XSS. Another issue is present in the Notification feature (OnlineBanking > Configuration > Notifications and alerts > Alerts *). The name of an alert is interpreted as HTML, and can thus embed JavaScript code, which is executed when displayed. This is a stored XSS. (Also, an issue is present in the File download feature, accessible via /OnlineBanking/cgi/isapi.dll/DOWNLOADFRS. When requesting to show the list of downloadable files, the contents of three form fields are embedded in the JavaScript code without prior sanitization. This is essentially a self-XSS.)
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sage XRT Business Exchange 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sage XRT Business Exchange是英国Sage公司的一部分 Sage 应用程序套件。 Sage XRT Business Exchange 12.4.302版本存在安全漏洞,该漏洞源于存在存储型XSS,允许攻击者在其他用户浏览器的上下文中执行JavaScript代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2022-34323

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-34323

登录查看更多情报信息。

Same Patch Batch · n/a · 2023-01-01 · 14 CVEs total

CVE-2021-41823Kemp Load Master 跨站脚本漏洞
CVE-2022-34322Sage Enterprise Intelligence 跨站脚本漏洞
CVE-2022-34324Sage XRT Business Exchange SQL注入漏洞
CVE-2022-37785WeCube 安全漏洞
CVE-2022-37786WeCube 安全漏洞
CVE-2022-37787WeCube 跨站脚本漏洞
CVE-2022-40711PrimeKey EJBCA 跨站脚本漏洞
CVE-2022-45027perfSONAR 代码问题漏洞
CVE-2022-45213perfSONAR 安全漏洞
CVE-2022-47634Isode M-Link 安全漏洞
CVE-2022-47952LXC 安全漏洞
CVE-2022-48198ntpd_driver 代码注入漏洞
CVE-2023-22551FTP 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2022-34323

No comments yet


Leave a comment