A CSV injection vulnerability was... CVE-2023-3527

- AV AC AU C I A
发布: 2023-07-18
修订: 2023-07-28

A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software such as Microsoft Excel.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息