PT-2020-16076 · Intermind · Intermind Imind Server
Andrey Skuratov
+1
·
Published
2020-11-05
·
Updated
2020-11-12
·
CVE-2020-25398
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InterMind iMind Server versions through 3.13.65
Description
The issue exists in the csv export functionality, allowing for CSV Injection.
Recommendations
For versions through 3.13.65, update to a version that contains a fix for this issue, as using the csv export functionality can lead to CSV Injection.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intermind Imind Server