Описание
Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the generated CSV report.
EPSS
Процентиль: 32%
0.00395
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-1236
Связанные уязвимости
CVSS3: 9.8
github
7 месяцев назад
Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the generated CSV report.
EPSS
Процентиль: 32%
0.00395
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-1236