Description


Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

Weaknesses



CWE-1236

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-1236

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-21T17:15:25.317Z

3 years ago

Last modified

2025-04-29T14:15:28.697Z

10 months ago