vendor:
projectSend
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
CSV Injection
78
CWE
Product Name: projectSend
Affected Version From: r1605
Affected Version To: r1605
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2023
projectSend r1605 – CSV injection
CSV injection vulnerability in projectSend r1605 allows remote attackers to execute arbitrary commands via a crafted payload in a CSV file. An attacker can exploit this vulnerability by creating a malicious CSV file containing a payload that will be executed when opened by an administrator using the Export action-log functionality.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input before using it to generate CSV files. Additionally, restrict access to the Export action-log functionality to trusted users only.