PT-2019-13631 · Joget · Joget Workflow

·

CVE-2019-14352

·

Publicado

2019-07-28

·

Atualizado

2024-08-05

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joget Workflow version 6.0.20
Description The issue exists in Joget Workflow, where CSV Injection, also known as Formula Injection, can occur. This is demonstrated by the "/jw/web/userview/crm community/crm userview sales/ /account new" endpoint with the Account ID or Account Name field. The vendor disputes the relevance of this finding, stating that CSV is not the intended export format for spreadsheet applications.
Recommendations For Joget Workflow version 6.0.20, consider restricting access to the "/jw/web/userview/crm community/crm userview sales/ /account new" endpoint to minimize the risk of exploitation, especially when using the Account ID or Account Name field. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-14352

Produtos afetados

Joget Workflow