Lucene search

K
osvGoogleOSV:CVE-2022-21241
HistoryFeb 08, 2022 - 11:15 a.m.

CVE-2022-21241

2022-02-0811:15:07
Google
osv.dev
7
cve-2022-21241
cross-site scripting
csv+
remote attacker
arbitrary script
arbitrary os command
specially crafted
csv file
html tag
software

AI Score

6.8

Confidence

High

EPSS

0.002

Percentile

59.4%

Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.

AI Score

6.8

Confidence

High

EPSS

0.002

Percentile

59.4%

Related for OSV:CVE-2022-21241