Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wc34-p4fh-wr9q

Опубликовано: 31 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in Archer Technology RSA Archer 6.11.00204.10014 allowing attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications.

An issue was discovered in Archer Technology RSA Archer 6.11.00204.10014 allowing attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications.

EPSS

Процентиль: 31%
0.0038
Низкий

8.8 High

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. NOTE: the Supplier does not accept this as a valid vulnerability report against their product.

CVSS3: 8.8
fstec
около 1 года назад

Уязвимость программная платформа для управления рисками RSA Archer, связанная с отсутствием нейтрализации элементов для файлов CSV, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 31%
0.0038
Низкий

8.8 High

CVSS3

Дефекты

CWE-1236