Show filters
62 Total Results
Displaying 21-30 of 62
Sort by:
Attacker Value
Unknown
CVE-2021-27839
Disclosure Date: March 03, 2021 (last updated February 22, 2025)
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.
0
Attacker Value
Unknown
CVE-2021-21302
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2
0
Attacker Value
Unknown
CVE-2020-9205
Disclosure Date: February 06, 2021 (last updated February 22, 2025)
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
0
Attacker Value
Unknown
CVE-2021-3188
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
0
Attacker Value
Unknown
CVE-2020-9200
Disclosure Date: December 24, 2020 (last updated February 22, 2025)
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
0
Attacker Value
Unknown
CVE-2019-16959
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
0
Attacker Value
Unknown
CVE-2020-28861
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.
0
Attacker Value
Unknown
CVE-2020-4633
Disclosure Date: December 10, 2020 (last updated February 22, 2025)
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
0
Attacker Value
Unknown
CVE-2020-4627
Disclosure Date: November 25, 2020 (last updated February 22, 2025)
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
0
Attacker Value
Unknown
CVE-2020-28845
Disclosure Date: November 20, 2020 (last updated February 22, 2025)
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
0