Описание
There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
6.8 Medium
CVSS3
6 Medium
CVSS2
Дефекты
Связанные уязвимости
There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
Уязвимость систем управления центрами обработки данных Huawei ManageOne, iManager NetEco, iManager NetEco 6000, связанная с отсутствием нейтрализации элементов в файле CSV, позволяющая нарушителю выполнить произвольный код
EPSS
6.8 Medium
CVSS3
6 Medium
CVSS2