Логотип exploitDog
bind:CVE-2023-53913
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53913

Количество 2

Количество 2

nvd логотип

CVE-2023-53913

около 2 месяцев назад

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rcqj-85jm-wmw8

около 2 месяцев назад

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53913

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-rcqj-85jm-wmw8

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу