CVE-2023-33410
Summary
| CVE | CVE-2023-33410 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-05 21:15:00 UTC |
| Updated | 2023-06-09 22:51:00 UTC |
| Description | Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is used to construct a CSV file. |
Risk And Classification
Problem Types: CWE-1236
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - Thirukrishnan/CVE-2023-33410 | MISC | github.com | |
| GitHub - minical/minical: Minical is an open-source PMS with extension management baked-in. It's designed for the companies looking for highly customizable property management software. | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.