PT-2021-12841 · Huawei · Manageone

Published

2021-02-06

·

Updated

2021-02-10

·

CVE-2020-9205

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: ManageOne version 8.0.1
Description: The issue is related to a CSV injection vulnerability. An attacker with common privilege may exploit this vulnerability through some operations to inject CSV files. The vulnerability is caused by insufficient input validation of some parameters, allowing the attacker to inject CSV files to the target device.
Recommendations: For ManageOne version 8.0.1, ensure proper input validation of parameters to prevent CSV injection. As a temporary workaround, consider restricting access to operations that may be used to inject CSV files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9205

Affected Products

Manageone