ZeroHour

CVE-2019-6182

CVSS 3.1
4.9 medium
EPSS
<1%p49
Published
()
Modified
Description

A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.

Vendors
lenovo
Products
xclarity administrator
Weakness
CWE-1236
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.