vendor:
Kibana
by:
Aamir Rehman
7.5
CVSS
HIGH
CSV Injection
N/A
CWE
Product Name: Kibana
Affected Version From: v6.6.1
Affected Version To: Latest versions
Patch Exists: NO
Related CWE: N/A
CPE: elastic:kibana
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Firefox/Windows
2020
Kibana 6.6.1 – CSV Injection
Kibana is an open source data visualization dashboard for Elasticsearch. It provides visualization capabilities on top of the content indexed on an Elasticsearch cluster. Most of the kibana applications are having authentication disabled any malicious user can inject csv payload in visualization section of dashboard and It's possible to run malicious command on logged in user computer.
Mitigation:
Enabling authentication for Kibana applications.