Описание
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.
Ссылки
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.1 (исключая)
cpe:2.3:a:luya:yii-helpers:*:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00396
Низкий
8 High
CVSS3
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-1236
CWE-1236
Связанные уязвимости
CVSS3: 7.8
github
почти 4 года назад
Improper neutralization of formula elements in yii-helpers
EPSS
Процентиль: 60%
0.00396
Низкий
8 High
CVSS3
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-1236
CWE-1236