vendor:
admidio
by:
Mirabbas Agalarov
7.4
CVSS
HIGH
CSV Injection
CWE
Product Name: admidio
Affected Version From: 4.2.2005
Affected Version To: 4.2.2005
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2023
admidio v4.2.5 – CSV Injection
Admidio is vulnerable to CSV injection when a malicious user sets their postal code to a specially crafted payload. If an admin then exports users as a CSV or Excel file, the payload will be executed on the admin's computer, in this case opening the calculator.
Mitigation:
Input validation should be used to prevent malicious payloads from being injected into the system.