Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg4q-mprj-p635

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.

Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.

EPSS

Процентиль: 73%
0.00789
Низкий

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.

EPSS

Процентиль: 73%
0.00789
Низкий

Дефекты

CWE-1236