PT-2025-1511 · Kwhotel · Kwhotel

6En6Ar

·

Published

2025-01-23

·

Updated

2025-02-04

·

CVE-2023-46401

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KWHotel version 0.47
Description The issue concerns CSV Formula Injection in the invoice adding function. This allows for potential exploitation through malicious formula injection in CSV files.
Recommendations For KWHotel version 0.47, consider disabling the invoice adding function until a patch is available to prevent CSV Formula Injection. Restrict access to the invoice management module to minimize the risk of exploitation. Avoid using the invoice adding feature with untrusted CSV files until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-02457
CVE-2023-46401

Affected Products

Kwhotel