PT-2022-17741 · Unknown · Surveyking

Strangej

·

Published

2022-03-24

·

Updated

2022-03-30

·

CVE-2022-26249

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Survey King version 0.3.0
Description The issue allows attackers to execute arbitrary code or access sensitive information via a CSV injection attack because Survey King does not filter data properly when exporting excel files.
Recommendations For Survey King version 0.3.0, consider implementing proper data filtering when exporting excel files to prevent CSV injection attacks. As a temporary workaround, restrict the export of sensitive information via excel files until a proper fix is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26249

Affected Products

Surveyking