Описание
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.19.23.5325 (исключая)
cpe:2.3:a:anuko:time_tracker:*:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01181
Низкий
8.7 High
CVSS3
7.3 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-74
CWE-1236
EPSS
Процентиль: 78%
0.01181
Низкий
8.7 High
CVSS3
7.3 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-74
CWE-1236