CVE-2018-20468

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/06/2019
Last modified:
24/08/2020

Description

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sahipro:sahi_pro:*:*:*:*:*:*:*:* 8.0.0 (including)


References to Advisories, Solutions, and Tools