PT-2018-18862 · Microbetrace · Microbetrace

West Shepherd

+1

·

Published

2018-04-26

·

Updated

2020-03-27

·

CVE-2018-9113

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MicrobeTRACE version 0.1.12
Description The issue allows remote attackers to execute arbitrary code, related to code injection via a crafted CSV file with an initial '><script type="text/javascript" src=' line.
Recommendations For MicrobeTRACE version 0.1.12, update to a version released after 2018-03-29 to resolve the issue. As a temporary workaround, consider restricting the import of CSV files or validating their content to prevent code injection attacks.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-9113

Affected Products

Microbetrace