A CSV injection vulnerability was found in the Avaya Call...
Moderate severity
Unreviewed
Published
Jul 19, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jul 18, 2023
Published to the GitHub Advisory Database
Jul 19, 2023
Last updated
Apr 4, 2024
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software
such as Microsoft Excel.
References