PT-2021-17635 · Unknown · Online Invoicing System

Jinson Varghese Behanan

·

Published

2021-03-03

·

Updated

2021-03-10

·

CVE-2021-27839

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Online Invoicing System (OIS) versions 4.3 and below
Description: A CSV injection issue allows users to perform malicious actions, such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.
Recommendations: For versions 4.3 and below, update to a version above 4.3 to resolve the issue. As a temporary workaround, consider restricting access to sensitive client details and implementing additional security measures to prevent redirection to harmful websites.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27839

Affected Products

Online Invoicing System