CVE-2022-23320: High severity Xerox Xmpie Ustore vulnerability
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23320?
CVE-2022-23320 is a vulnerability in XMPie uStore 12.3.7244.0 that allows administrators to generate reports based on raw SQL queries.
What is the severity of CVE-2022-23320?
The severity of CVE-2022-23320 is high, with a severity value of 7.5.
How does CVE-2022-23320 affect XMPie uStore?
CVE-2022-23320 allows attackers with default administrative credentials to authenticate into XMPie uStore 12.3.7244.0 and exfiltrate sensitive information from the database.
How can I fix CVE-2022-23320?
To fix CVE-2022-23320, it is recommended to update XMPie uStore to a version that resolves the vulnerability.
Where can I find more information about CVE-2022-23320?
More information about CVE-2022-23320 can be found at the following references: http://xmpie.com, https://www.linkedin.com/feed/update/urn:li:activity:6894666176450887681?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A6894666176450887681%2C6895051709354192896%29, https://www.triaxiomsecurity.com/xmpie-ustore-vulnerabilities-discovered/