CVE-2024-9102

Published

Severity

CVSS v3:
N/A
CVSS v2:
N/A

Description

phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. Thus, this could lead to CSV Formula Injection.

References

Configurations

CPE23Version StartVersion EndExact Version

External Links