Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g26q-ppp8-jj4r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.

A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.

EPSS

Процентиль: 45%
0.00224
Низкий

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 4.4
nvd
почти 5 лет назад

A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.

EPSS

Процентиль: 45%
0.00224
Низкий

Дефекты

CWE-1236