Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99wc-g6xm-mv9h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export.

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export.

EPSS

Процентиль: 64%
0.00475
Низкий

8.8 High

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export.

EPSS

Процентиль: 64%
0.00475
Низкий

8.8 High

CVSS3

Дефекты

CWE-1236