CVE-2019-6187

MEDIUM

Lenovo XClarity Controller - CSV Injection

Title source: llm
STIX 2.1

Description

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

Scores

CVSS v3 6.5
EPSS 0.0040
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-1236
Status published
Products (1)
lenovo/xclarity_controller < tei392m
Published Nov 20, 2019
Tracked Since Feb 18, 2026