PT-2025-1511 · Kwhotel · Kwhotel

·

CVE-2023-46401

·

Published

2025-01-23

·

Updated

2025-02-04

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KWHotel version 0.47
Description The issue concerns CSV Formula Injection in the invoice adding function. This allows for potential exploitation through malicious formula injection in CSV files.
Recommendations For KWHotel version 0.47, consider disabling the invoice adding function until a patch is available to prevent CSV Formula Injection. Restrict access to the invoice management module to minimize the risk of exploitation. Avoid using the invoice adding feature with untrusted CSV files until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02457
CVE-2023-46401

Affected Products

Kwhotel