Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvmh-jgw7-f7xg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

EPSS

Процентиль: 66%
0.00509
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
около 6 лет назад

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

EPSS

Процентиль: 66%
0.00509
Низкий