PT-2024-13261 · Unknown · Ailux Imx6 Bundle

Andrea Palanca

·

Published

2024-03-05

·

Updated

2024-03-05

·

CVE-2023-45597

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AiLux imx6 bundle versions prior to imx6 1.0.7-2
Description A CWE-1236 issue in the file configuration functionality of the web application, concerning the export file function, allows a remote authenticated attacker to inject arbitrary formulas inside generated CSV files.
Recommendations For versions prior to imx6 1.0.7-2, update to version imx6 1.0.7-2 or later to resolve the issue. As a temporary workaround, consider restricting access to the export file function until a patch is available. Avoid using the file configuration functionality in the web application until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-45597

Affected Products

Ailux Imx6 Bundle