Логотип exploitDog
bind:CVE-2018-25135
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-25135

Количество 2

Количество 2

nvd логотип

CVE-2018-25135

около 2 месяцев назад

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-58r7-rx7j-5v4g

около 2 месяцев назад

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-25135

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-58r7-rx7j-5v4g

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу