Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3v5g-248q-q8gh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.

A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.

EPSS

Процентиль: 44%
0.00217
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 4.9
nvd
больше 6 лет назад

A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.

EPSS

Процентиль: 44%
0.00217
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-1236