CVE-2022-41399
28.04.2023, 13:15
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to the SQL database.Enginsight
Vendor | Product | Version |
---|---|---|
sage | sage_300 | 𝑥 ≤ 2022 |
𝑥
= Vulnerable software versions