vendor:
ERPGo SaaS
by:
Sajibe Kanti
8.8
CVSS
HIGH
CSV Injection
CWE
Product Name: ERPGo SaaS
Affected Version From: 3.9
Affected Version To: 3.9
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows & Live Litespeed Web Server
2023
ERPGo SaaS 3.9 – CSV Injection
ERPGo is a software as a service (SaaS) platform that is vulnerable to CSV injection attacks. This type of attack occurs when an attacker is able to manipulate the data that is imported or exported in a CSV file, in order to execute malicious code or gain unauthorized access to sensitive information. This vulnerability can be exploited by an attacker by injecting specially crafted data into a CSV file, which is then imported into the ERPGo system. This can potentially allow the attacker to gain access to sensitive information, such as login credentials or financial data, or to execute malicious code on the system.
Mitigation:
Ensure that all CSV files are properly validated before being imported into the system, and that any data that is imported is sanitized to prevent malicious code from being executed.