CVE-2021-27839
Summary
| CVE | CVE-2021-27839 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-03 19:15:00 UTC |
| Updated | 2021-03-10 17:36:00 UTC |
| Description | A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to. |
Risk And Classification
Problem Types: CWE-1236
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bigprof | Online Invoicing System | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release OIS 4.4 · bigprof-software/online-invoicing-system · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| CSV Injection in Online Invoicing System (OIS) | MISC | www.jinsonvarghese.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.