Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HCorebos
APPCorebos≤ 8.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2023-3069CRITICAL9.8PL ✓ten sam produkt
Zmiana hasła bez weryfikacji tożsamości w Corebos
CVE-2022-4446CRITICAL9.8PL ✓ten sam produkt
PHP Remote File Inclusion w repozytorium coreBOS (RCE bez uwierzytelnienia)
CVE-2023-3075MEDIUM6.5ten sam produkt
Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8.
CVE-2023-3073MEDIUM5.4ten sam produkt
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc.
CVE-2023-3074MEDIUM5.4ten sam produkt
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.