Описание
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.
EPSS
Процентиль: 93%
0.10226
Средний
9.8 Critical
CVSS3
Дефекты
CWE-1236
Связанные уязвимости
CVSS3: 9.8
github
почти 2 года назад
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.
EPSS
Процентиль: 93%
0.10226
Средний
9.8 Critical
CVSS3
Дефекты
CWE-1236