CVE-2023-33410
HIGHMinical <= 1.0.0 - CSV Injection via Customer Name Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-33410. PoCs published by Thirukrishnan.
AI-analyzed exploit summary This PoC demonstrates a CSV Injection vulnerability in Minical 1.0.0, where a malicious payload is injected into the Name field of the Accounting module, which then gets rendered when a CSV report is downloaded.
Description
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is used to construct a CSV file.
Exploits (1)
This PoC demonstrates a CSV Injection vulnerability in Minical 1.0.0, where a malicious payload is injected into the Name field of the Accounting module, which then gets rendered when a CSV report is downloaded.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H