CSV Injection Vulnerability in Car Rental Script by PHPJabbers
CVE-2023-48835
8.8HIGH
Summary
The Car Rental Script v3.0 by PHPJabbers is susceptible to CSV Injection, which occurs through the Language > Labels > Export function. This vulnerability allows unauthorized users to manipulate exported CSV files, potentially leading to data exfiltration and execution of arbitrary commands when files are opened in spreadsheet applications. It is crucial for users of this script to apply security measures to prevent exploitation and safeguard sensitive information.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved