PT-2026-48447 · Unknown · Migration-Planner
CVE-2026-53474
·
Published
2026-06-10
·
Updated
2026-09-04
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
migration-planner (affected versions not specified)
Description
A remote authenticated attacker can exploit a flaw by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed during the processing of cluster names. This SQL Injection enables arbitrary file reading on the system, which may expose sensitive data such as Kubernetes service account tokens and other credentials, potentially leading to a full compromise of the SaaS environment.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Migration-Planner