Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpqq-223w-7pwh

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.2
CVSS3: 8.8

Описание

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.

EPSS

Процентиль: 16%
0.00052
Низкий

6.2 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 8
nvd
около 2 месяцев назад

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.

EPSS

Процентиль: 16%
0.00052
Низкий

6.2 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-1236