The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.
References
Link | Resource |
---|---|
https://www.themissinglink.com.au/security-advisories/cve-2022-40294 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: TML
Published: 2022-10-31T20:09:23.823821Z
Updated: 2023-10-25T08:26:30.471Z
Reserved: 2022-09-08T00:00:00
Link: CVE-2022-40294
JSON object: View
NVD Information
Status : Modified
Published: 2022-10-31T21:15:13.167
Modified: 2023-10-25T18:17:16.443
Link: CVE-2022-40294
JSON object: View
Redhat Information
No data.
CWE