Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5299

Опубликовано: 03 июн. 2020
Источник: nvd
CVSS3: 4
CVSS3: 5.1
CVSS2: 4.6
EPSS Низкий

Описание

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the ImportExportController could potentially introduce a CSV injection into the data to cause the generated CSV export file to be malicious. This requires attackers to achieve the following before a successful attack can be completed: 1. Have found a vulnerability in the victims spreadsheet software of choice. 2. Control data that would potentially be exported through the ImportExportController by a theoretical victim. 3. Convince the victim to export above data as a CSV and run it in vulnerable spreadsheet software while also bypassing any sanity checks by said software. Issue has been patched in Build 466 (v1.0.466).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
Версия от 1.0.319 (включая) до 1.0.466 (исключая)

EPSS

Процентиль: 71%
0.00673
Низкий

4 Medium

CVSS3

5.1 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-77
CWE-77

Связанные уязвимости

CVSS3: 4
github
больше 5 лет назад

Potential CSV Injection vector in OctoberCMS

EPSS

Процентиль: 71%
0.00673
Низкий

4 Medium

CVSS3

5.1 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-77
CWE-77