Unknown · Sesami Cash Point & Transport Optimizer · CVE-2023-31295
**Name of the Vulnerable Software and Affected Versions**
Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6
**Description**
The issue allows remote attackers to obtain sensitive information via the `User Profile` field. This is a CSV Injection vulnerability, which can be exploited by attackers to gain access to sensitive data.
**Recommendations**
For Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6, consider restricting access to the `User Profile` field until a patch is available. As a temporary workaround, avoid using the `User Profile` field in remote interactions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.