Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the vendor disputes the relevance of this finding because CSV is not the intended export format for spreadsheet applications
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Joget Workflow 输入验证错误漏洞
Vulnerability Description
Joget Workflow是美国Joget公司的一套基于Web的开源工作流软件。该软件主要用于开发工作流和业务流程管理应用程序 Joget Workflow 6.0.20版本中存在CSV注入漏洞 。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
CVSS Information
N/A
Vulnerability Type
N/A