Логотип exploitDog
bind:CVE-2021-38180
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-38180

Количество 2

Количество 2

nvd логотип

CVE-2021-38180

больше 4 лет назад

SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to execute macros while opening the file and the security settings of Excel allow for command execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-h8r6-3pj7-gwfh

больше 3 лет назад

SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to execute macros while opening the file and the security settings of Excel allow for command execution.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-38180

SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to execute macros while opening the file and the security settings of Excel allow for command execution.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-h8r6-3pj7-gwfh

SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to execute macros while opening the file and the security settings of Excel allow for command execution.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу