vendor:
by:
Ranjeet Jaiswal
5.5
CVSS
MEDIUM
CSV Injection
79
CWE
Product Name:
Affected Version From: 10.8.2004
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
RosarioSIS 10.8.4 – CSV Injection
A CSV Injection vulnerability in the RosarioSIS web application with version 10.8.4 allows malicious users to execute malicious payload in csv/xls and redirect authorized user to malicious website.
Mitigation:
Upgrade to latest release of RosarioSIS