漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ERPGo SaaS 3.9 CSV Injection via Vendor Creation
Vulnerability Description
ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas into vendor name fields that execute on the workstation of users who open the exported CSV in a spreadsheet application. Attackers can add malicious formulas like =10+20+cmd|' /C calc'!A0 in the vendor creation form, which execute when the exported CSV file is opened in spreadsheet applications.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1236
Vulnerability Title
Rajodiya ERPGo SaaS 安全漏洞
Vulnerability Description
Rajodiya ERPGo SaaS是Rajodiya公司的一个在线企业资源规划系统。 Rajodiya ERPGo SaaS 3.9版本存在安全漏洞,该漏洞源于CSV注入漏洞,允许经过身份验证的攻击者通过向供应商名称字段注入公式有效载荷执行任意代码,在供应商创建表单中添加恶意公式如=10+20+cmd| /C calc !A0,当导出的CSV文件在电子表格应用程序中打开时执行。
CVSS Information
N/A
Vulnerability Type
N/A