CVE-2018-20468

HIGH

Tyto Sahi Pro <8.0.0 - Code Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code execution.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://barriersec.com/2019/06/cve-2018-20468-sahi-pro/

Scores

CVSS v3 8.8
EPSS 0.0222
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-1236
Status published
Products (1)
sahipro/sahi_pro < 8.0.0
Published Jun 17, 2019
Tracked Since Feb 18, 2026