shorooq-hummdi/Archer-csv-injection-command-exec

shorooq-hummdi/Archer-csv-injection-command-exec

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. NOTE: the Supplier does not accept this as a valid vulnerability report against their product.