CVE-2023-45597
A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “export_file”) allows a remote authenticated attacker to inject arbitrary formulas inside generated CSV files.
A remote authenticated attacker, by inducing victims into downloading and opening the poisoned content, may execute arbitrary code in the victims’ workstations, or leak confidential information.
March 4, 2024
This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
CVE-2023-45597
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
5.9
Update to imx6 bundle version imx6_1.0.7-2.
Andrea Palanca of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

