iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-04-15T17:43:05.871Z

Updated: 2024-08-02T21:37:54.693Z

Reserved: 2023-11-17T19:43:37.555Z

Link: CVE-2023-48709

cve-icon Vulnrichment

Updated: 2024-08-02T21:37:54.693Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-15T18:15:08.877

Modified: 2024-04-15T19:12:25.887

Link: CVE-2023-48709

cve-icon Redhat

No data.