PT-2021-17635 · Unknown · Online Invoicing System
Jinson Varghese Behanan
·
Published
2021-03-03
·
Updated
2021-03-10
·
CVE-2021-27839
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Online Invoicing System (OIS) versions 4.3 and below
Description:
A CSV injection issue allows users to perform malicious actions, such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.
Recommendations:
For versions 4.3 and below, update to a version above 4.3 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive client details and implementing additional security measures to prevent redirection to harmful websites.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Invoicing System