Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xr4-xcg2-6xq7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.

An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.

EPSS

Процентиль: 35%
0.00143
Низкий

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 3.7
nvd
больше 4 лет назад

An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.

EPSS

Процентиль: 35%
0.00143
Низкий

Дефекты

CWE-1236