Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19676

Опубликовано: 18 мар. 2020
Источник: nvd
CVSS3: 9.6
CVSS2: 9.3
EPSS Низкий

Описание

A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:arxes-tolina:arxes-tolina:3.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 63%
0.00443
Низкий

9.6 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-1236

Связанные уязвимости

github
больше 3 лет назад

A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.

EPSS

Процентиль: 63%
0.00443
Низкий

9.6 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-1236