CVE-2019-6187

MEDIUM

Lenovo XClarity Controller - CSV Injection

Title source: llm
STIX 2.1

Description

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://support.lenovo.com/solutions/LEN-29118

Scores

CVSS v3 6.5
EPSS 0.0086
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-1236
Status published
Products (1)
lenovo/xclarity_controller < tei392m
Published Nov 20, 2019
Tracked Since Feb 18, 2026