Description
A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inserting spreadsheet formulas in macro names.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiAnalyzer version 7.2.2 or above Please upgrade to FortiAnalyzer version 7.0.6 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29552 | A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inserting spreadsheet formulas in macro names. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-488 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:48:54.796Z
Reserved: 2023-02-08T13:42:03.367Z
Link: CVE-2023-25611
Updated: 2024-08-02T11:25:19.259Z
Status : Modified
Published: 2023-03-07T17:15:12.877
Modified: 2024-11-21T07:49:49.700
Link: CVE-2023-25611
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD