PT-2019-13631 · Joget · Joget Workflow
Ghost
·
Published
2019-07-28
·
Updated
2024-08-05
·
CVE-2019-14352
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Joget Workflow version 6.0.20
Description
The issue exists in Joget Workflow, where CSV Injection, also known as Formula Injection, can occur. This is demonstrated by the "/jw/web/userview/crm community/crm userview sales/ /account new" endpoint with the
Account ID or Account Name field. The vendor disputes the relevance of this finding, stating that CSV is not the intended export format for spreadsheet applications.Recommendations
For Joget Workflow version 6.0.20, consider restricting access to the "/jw/web/userview/crm community/crm userview sales/ /account new" endpoint to minimize the risk of exploitation, especially when using the
Account ID or Account Name field. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joget Workflow