Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-64045
HistoryAug 15, 2023 - 12:00 a.m.

ChurchCRM CSV Injection Vulnerability (CNVD-2023-64045)

2023-08-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
churchcrm
csv injection
vulnerability

EPSS

0.003

Percentile

68.8%

ChurchCRM is an open source CRM system for churches. ChurchCRM version 4.2.0 suffers from a CSV injection vulnerability that originates from improperly neutralized formula elements in a CSV file, which can be exploited by a remote attacker to execute arbitrary code via a crafted CSV file.

EPSS

0.003

Percentile

68.8%

Related for CNVD-2023-64045