RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.
References
Link | Resource |
---|---|
https://gitee.com/y_project/RuoYi/issues/I4RBBD | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2022-03-30 04:15
Updated : 2022-04-04 12:47
NVD link : CVE-2022-23868
Mitre link : CVE-2022-23868
JSON object : View
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Products Affected
ruoyi
- ruoyi