QID 730335
Date Published: 2022-01-25
QID 730335: Joget Workflow CSV Injection Vulnerability
Joget Workflow is an open-source web-based workflow software to develop workflow and business process management applications.
CVE-2019-14352: *DISPUTED* CSV Injection, also known as Formula Injection exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field.
Affected Versions:
Joget Workflow 6.0.20
QID Detection Logic (Unauthenticated) :
Joget Workflow version is fetched by sending GET request to "/jw/web/login" page.
Successful exploitation of this vulnerability could allow a remote authenticated attacker to exfiltrate contents from the spreadsheet, or other open spreadsheets.
Solution
Please refer to following Joget Advisory advisory for recommending mitigations.
Vendor References
- Joget Workflow Advisory -
github.com/jogetworkflow/jw-community/issues/20
CVEs related to QID 730335
Software Advisories
| Advisory ID | Software | Component | Link |
|---|