漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “Notes” functionality in the main screen, an attacker can inject a payload into the “Description” field under the “Insert To-Do” option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a software such as Microsoft Excel. The attacker could gain remote access to the user’s PC.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Marmind 安全漏洞
Vulnerability Description
Marmind是奥地利Marmind公司的一个用于管理协调营销活动的Web平台。该平台将营销预算和组合结果组合到一个营销计划中,供使用者进行分析。 Marmind web application 4.1.141.0 版本存在注入漏洞,该漏洞允许恶意用户获得对其他计算机的远程控制。
CVSS Information
N/A
Vulnerability Type
N/A