CVE-2022-40294

HIGH

CSV Injection - Code Injection

Title source: llm
STIX 2.1

Description

The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.

Scores

CVSS v3 8.8
EPSS 0.0050
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1236
Status published
Products (1)
phppointofsale/php_point_of_sale 19.0
Published Oct 31, 2022
Tracked Since Feb 18, 2026