Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vm5p-28rv-rr68

Опубликовано: 21 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

EPSS

Процентиль: 91%
0.06532
Низкий

7.8 High

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 7.8
nvd
около 3 лет назад

Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

EPSS

Процентиль: 91%
0.06532
Низкий

7.8 High

CVSS3

Дефекты

CWE-1236