Описание
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:event_registration_application_project:event_registration_application:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06532
Низкий
7.8 High
CVSS3
Дефекты
CWE-1236
CWE-1236
Связанные уязвимости
CVSS3: 7.8
github
около 3 лет назад
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.
EPSS
Процентиль: 91%
0.06532
Низкий
7.8 High
CVSS3
Дефекты
CWE-1236
CWE-1236