vendor:
AIM CrossChex Standard
by:
Gjoko 'LiquidWorm' Krstic
7.8
CVSS
HIGH
CSV Injection
N/A
CWE
Product Name: AIM CrossChex Standard
Affected Version From: 4.3.6.0
Affected Version To: 4.3.6.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN)
2018
Anviz AIM CrossChex Standard 4.3 – CSV Injection
CSV (XLS) Injection (Excel Macro Injection or Formula Injection) exists in the AIM CrossChex 4.3 when importing or exporting users using xls Excel file. This can be exploited to execute arbitrary commands on the affected system via SE attacks when an attacker inserts formula payload in the 'Name' field when adding a user or using the custom fields 'Gender', 'Position', 'Phone', 'Birthday', 'Employ Date' and 'Address'. Upon importing, the application will launch Excel program and execute the malicious macro formula.
Mitigation:
N/A