---
id: CVE-2022-23320
title: >-
  XMPie uStore 12.3.7244.0 allows for administrators to generate reports based
  on raw SQL queries
summary: >-
  XMPie uStore 12.3.7244.0 allows for administrators to generate reports based
  on raw SQL queries. Since the application ships with default administrative
  credentials, an attacker may authenticate into the application and exfiltrate
  sensit…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-287
vendor: xerox
product: xmpie_ustore
affected:
  - xmpie_ustore = 12.3.7244.0
published: '2022-02-07'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23320'
references:
  - url: >-
      https://www.linkedin.com/feed/update/urn:li:activity:6894666176450887681?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A6894666176450887681%2C6895051709354192896%29
    label: cve@mitre.org
  - url: 'https://www.triaxiomsecurity.com/xmpie-ustore-vulnerabilities-discovered/'
    label: cve@mitre.org
  - url: 'https://www.xmpie.com/ustore-release-notes/'
    label: cve@mitre.org
  - url: 'http://xmpie.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.linkedin.com/feed/update/urn:li:activity:6894666176450887681?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A6894666176450887681%2C6895051709354192896%29
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.triaxiomsecurity.com/xmpie-ustore-vulnerabilities-discovered/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.xmpie.com/ustore-release-notes/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01644
epssPercentile: 0.75408
ingestedAt: '2026-07-06T17:03:23.894Z'
---

## Overview

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.

## Affected

- `xmpie_ustore = 12.3.7244.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
