216.73.216.133

CVE-2024-9102

· Published 19/12/2024 14:15 · Modified 19/12/2024 14:15

Labels: CVE-2024-9102 2024-12-19CVE-2024-9102CWE-1236[email protected]

Essential information

Published
19/12/2024 14:15
Modified
19/12/2024 14:15
Author
Creator
CISA KEV
No
CWE

Description

phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. Thus, this could lead to CSV Formula Injection.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References