CSV Injection Vulnerability in Ericsson ECM User Profile Management
CVE-2021-41390

8HIGH

Key Information:

Vendor

Ericsson

Vendor
CVE Published:
17 September 2021

What is CVE-2021-41390?

The Security Provider Endpoint in the User Profile Management Section of Ericsson ECM, prior to version 18.0, is susceptible to CSV Injection attacks. This vulnerability allows an attacker to manipulate data inappropriately, potentially leading to unauthorized access or data manipulation when CSV files are processed. Proper validation and sanitization of user input are crucial to mitigate this risk effectively.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-41390 : CSV Injection Vulnerability in Ericsson ECM User Profile Management