A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-03-03T18:11:32
Updated: 2024-08-03T21:33:16.053Z
Reserved: 2021-03-01T00:00:00
Link: CVE-2021-27839
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-03-03T19:15:13.047
Modified: 2024-11-21T05:58:37.593
Link: CVE-2021-27839
Redhat
No data.