8.8
CVSSv3

CVE-2018-9106

Published: 28/03/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension prior to 3.5.1 for Joomla! via a value that is mishandled in a CSV export.

Vulnerable Product Search on Vulmon Subscribe to Product

acyba acysms

Exploits

# Exploit Title: Joomla! Component AcySMS 350 CSV Macro Injection # Google Dork: N/A # Date: 22-03-2018 ################################ # Exploit Author: Sureshbabu Narvaneni ################################ # Vendor Homepage: wwwacybacom # Software Link: extensionsjoomlaorg/extensions/extension/communication/phone-a-sms/acys ...
Joomla AcySMS component version 350 suffers from a CSV macro injection vulnerability ...