CSV Injection Vulnerability in Ericsson ECM User Profile Management
CVE-2021-41390
8HIGH
What is CVE-2021-41390?
The Security Provider Endpoint in the User Profile Management Section of Ericsson ECM, prior to version 18.0, is susceptible to CSV Injection attacks. This vulnerability allows an attacker to manipulate data inappropriately, potentially leading to unauthorized access or data manipulation when CSV files are processed. Proper validation and sanitization of user input are crucial to mitigate this risk effectively.