漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Vulnerability Type
CWE-1236
Vulnerability Title
Dell EMC PowerStore 安全漏洞
Vulnerability Description
Dell EMC PowerStore是美国戴尔(Dell)公司的一款存储设备。 Dell EMC PowerStore v2.1.1.0版本存在安全漏洞,该漏洞源于数据按原样获取,无需任何验证或消毒。攻击者利用该漏洞可以注入有效载荷。
CVSS Information
N/A
Vulnerability Type
N/A