漏洞标题
Incorta Edit Insight csv 注入漏洞
漏洞描述信息
在Incorta 2023.4.3版本中发现了一个漏洞,已被分类为具有问题性的漏洞。该漏洞影响了组件Edit Insight Handler中的未知功能。通过操纵参数Service Name,可以导致CSV注入。此攻击可以通过远程方式进行。供应商已被提前联系以告知此漏洞披露情况,但未对此作出任何回应。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
漏洞类别
CWE-1236
漏洞标题
Incorta Edit Insight csv injection
漏洞描述信息
A vulnerability was found in Incorta 2023.4.3. It has been classified as problematic. Affected is an unknown function of the component Edit Insight Handler. The manipulation of the argument Service Name leads to csv injection. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
漏洞类别
N/A