Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53474

Опубликовано: 10 июн. 2026
Источник: nvd
CVSS3: 9.6
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Injection allows for arbitrary file reading on the system, potentially exposing sensitive information such as Kubernetes service account tokens and other credentials, which could lead to a full compromise of the SaaS environment.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kebev2v:migration_assessment:*:*:*:*:*:*:*:*
Версия до 0.13.5 (исключая)

EPSS

Процентиль: 22%
0.00298
Низкий

9.6 Critical

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.6
redhat
около 2 месяцев назад

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Injection allows for arbitrary file reading on the system, potentially exposing sensitive information such as Kubernetes service account tokens and other credentials, which could lead to a full compromise of the SaaS environment.

CVSS3: 9.6
github
около 2 месяцев назад

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Injection allows for arbitrary file reading on the system, potentially exposing sensitive information such as Kubernetes service account tokens and other credentials, which could lead to a full compromise of the SaaS environment.

EPSS

Процентиль: 22%
0.00298
Низкий

9.6 Critical

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-89