9.3
CVSSv2

CVE-2015-5349

Published: 11/04/2016 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The CSV export in Apache LDAP Studio and Apache Directory Studio prior to 2.0.0-M10 does not properly escape field values, which might allow malicious users to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache ldap studio 0.6.0

apache ldap studio 0.7.0

apache ldap studio 0.8.0

apache ldap studio 0.8.1

apache directory studio 1.0.0

apache directory studio 1.0.1

apache directory studio 1.1.0

apache directory studio 1.2.0

apache directory studio 1.3.0

apache directory studio 1.4.0

apache directory studio 1.5.0

apache directory studio 1.5.1

apache directory studio 1.5.2

apache directory studio 1.5.3

apache directory studio 2.0.0