iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-04-15T17:43:05.871Z

Updated: 2024-06-17T20:05:33.014Z

Reserved: 2023-11-17T19:43:37.555Z


Link: CVE-2023-48709

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-04-15T18:15:08.877

Modified: 2024-04-15T19:12:25.887


Link: CVE-2023-48709

JSON object: View

cve-icon Redhat Information

No data.