ZeroHour

CVE-2021-43257

PoC
CVSS 3.1
7.8 high
EPSS
<1%p60
Published
()
Modified
Description

Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.

Vendors
mantisbt
Products
mantisbt
Weakness
CWE-1236
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.