Description
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-21240 | CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file. |
References
| Link | Providers |
|---|---|
| https://github.com/ChurchCRM/CRM/issues/5465 |
|
History
Wed, 09 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-09T18:42:39.185Z
Reserved: 2020-11-16T00:00:00.000Z
Link: CVE-2020-28848
Updated: 2024-08-04T16:40:59.965Z
Status : Modified
Published: 2023-08-11T14:15:11.170
Modified: 2026-06-17T03:10:44.830
Link: CVE-2020-28848
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
EUVD