Логотип exploitDog
bind:CVE-2022-26867
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-26867

Количество 2

Количество 2

nvd логотип

CVE-2022-26867

больше 3 лет назад

PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-w9qh-pvx2-rhmh

больше 3 лет назад

PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-26867

PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w9qh-pvx2-rhmh

PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.

CVSS3: 8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу