Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxj6-2w57-fchv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

EPSS

Процентиль: 72%
0.00745
Низкий

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

CVSS3: 7.8
debian
почти 4 года назад

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV ...

EPSS

Процентиль: 72%
0.00745
Низкий

Дефекты

CWE-1236