PT-2019-13631 · Joget · Joget Workflow

Ghost

·

Published

2019-07-28

·

Updated

2024-08-05

·

CVE-2019-14352

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joget Workflow version 6.0.20
Description The issue exists in Joget Workflow, where CSV Injection, also known as Formula Injection, can occur. This is demonstrated by the "/jw/web/userview/crm community/crm userview sales/ /account new" endpoint with the Account ID or Account Name field. The vendor disputes the relevance of this finding, stating that CSV is not the intended export format for spreadsheet applications.
Recommendations For Joget Workflow version 6.0.20, consider restricting access to the "/jw/web/userview/crm community/crm userview sales/ /account new" endpoint to minimize the risk of exploitation, especially when using the Account ID or Account Name field. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2019-14352

Affected Products

Joget Workflow