Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-48029

Опубликовано: 17 нояб. 2023
Источник: nvd
CVSS3: 8
EPSS Низкий

Описание

Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:corebos:corebos:*:*:*:*:*:*:*:*
Версия до 8.0 (включая)

EPSS

Процентиль: 59%
0.0038
Низкий

8 High

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 8
github
около 2 лет назад

Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer.

EPSS

Процентиль: 59%
0.0038
Низкий

8 High

CVSS3

Дефекты

CWE-1236