Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fw85-97w2-fp5v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.

Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.

EPSS

Процентиль: 44%
0.00214
Низкий

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 3.5
nvd
почти 5 лет назад

Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.

EPSS

Процентиль: 44%
0.00214
Низкий

Дефекты

CWE-116