CSV Injection Vulnerability in OPSWAT MetaDefender Products
CVE-2018-16275

7.8HIGH

Key Information:

Vendor

Opswat

Vendor
CVE Published:
31 August 2018

What is CVE-2018-16275?

OPSWAT MetaDefender versions prior to v4.11.2 are susceptible to a CSV injection vulnerability that could allow an attacker to manipulate CSV files. This exploitation may lead to deceptive user interfaces and data breaches, affecting the integrity and security of information processed by the application. Users and organizations utilizing OPSWAT MetaDefender should upgrade to the latest version to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.