PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.
References
Link Resource
https://www.dell.com/support/kbdoc/000196367 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: dell

Published: 2022-04-19T00:00:00

Updated: 2022-06-02T21:00:25

Reserved: 2022-03-10T00:00:00


Link: CVE-2022-26867

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-02T21:15:07.667

Modified: 2022-06-13T16:41:58.033


Link: CVE-2022-26867

JSON object: View

cve-icon Redhat Information

No data.

CWE