PT-2023-4136 · Phpmyfaq · Phpmyfaq

Publicado

2023-07-30

·

Atualizado

2023-08-03

·

CVE-2023-4006

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 3.1.16
Description The issue is related to the improper neutralization of formula elements in a CSV file, which can be exploited by a remote attacker to access confidential data, compromise data integrity, and cause a denial of service using a specially crafted CSV file. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For versions prior to 3.1.16, update to version 3.1.16 or later to resolve the issue. As a temporary workaround, consider restricting access to CSV file uploads or disabling the feature that allows users to upload CSV files until a patch is applied. Avoid using the CSV file type in the affected API endpoint until the issue is resolved.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04445
CVE-2023-4006
GHSA-2XVX-368H-QCMV

Produtos afetados

Phpmyfaq