Back to search
CVE-2019-6187
Published: Nov 20, 2019
Modified: Sep 17, 2024
PUBLISHED
Description
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
| Vendor | Product | Versions |
|---|---|---|
Lenovo | Lenovo XClarity Controller (XCC) | affected unspecified - < TEI392Maffected unspecified - < CDI340Maffected unspecified - < G1I312affected unspecified - < PSI328M |
References
https://support.lenovo.com/solutions/LEN-29118
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now