CVE-2018-15474

CVE-2018-15474

** DISPUTED ** CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki."

Source: CVE-2018-15474

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다