PT-2026-49236 · Media Technology · Pizzy Library
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pizzy Library versions 1.0.0.26250 through 1.3.9.26250
Description
Improper neutralization of formula elements in a CSV file in MIA Technology Inc. Pizzy Library allows Code Injection, which occurs when an application fails to properly sanitize user-supplied input before including it in a CSV file, potentially allowing the execution of arbitrary code via spreadsheet formulas.
Recommendations
Update Pizzy Library to version 1.3.9.26250 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pizzy Library