7.3
CVSSv3

CVE-2020-15255

Published: 16/10/2020 Updated: 18/11/2021
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.3 | Impact Score: 5.9 | Exploitability Score: 1.3
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

anuko time tracker

Exploits

Anuko Time Tracker version 119235325 suffers from a CSV formula injection vulnerability ...