PT-2024-13261 · Unknown · Ailux Imx6 Bundle

·

CVE-2023-45597

·

Published

2024-03-05

·

Updated

2024-03-05

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AiLux imx6 bundle versions prior to imx6 1.0.7-2
Description A CWE-1236 issue in the file configuration functionality of the web application, concerning the export file function, allows a remote authenticated attacker to inject arbitrary formulas inside generated CSV files.
Recommendations For versions prior to imx6 1.0.7-2, update to version imx6 1.0.7-2 or later to resolve the issue. As a temporary workaround, consider restricting access to the export file function until a patch is available. Avoid using the file configuration functionality in the web application until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-45597

Affected Products

Ailux Imx6 Bundle