vendor:
Rukovoditel
by:
Mirabbas Agalarov
N/A
CVSS
N/A
CSV Injection
CWE
Product Name: Rukovoditel
Affected Version From: 3.3.2001
Affected Version To: 3.3.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
Rukovoditel 3.3.1 – CSV injection
The Rukovoditel version 3.3.1 is vulnerable to CSV injection. By setting the Firstname field as '=calc|a!z|', an attacker can trigger a CSV injection attack and open the calculator on the admin's computer when the admin exports customers as a CSV file.