Vulnerabilities > CVE-2018-10255 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Clustercoding Blog Master PRO 1.0.0

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
clustercoding
CWE-1236
exploit available

Summary

A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

Vulnerable Configurations

Part Description Count
Application
Clustercoding
1

Exploit-Db

descriptionBlog Master Pro 1.0 - CSV Injection. CVE-2018-10255. Webapps exploit for PHP platform
fileexploits/php/webapps/44535.txt
idEDB-ID:44535
last seen2018-05-24
modified2018-04-25
platformphp
port
published2018-04-25
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44535/
titleBlog Master Pro 1.0 - CSV Injection
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/147363/blogmasterpro10-inject.txt
idPACKETSTORM:147363
last seen2018-04-27
published2018-04-26
reporter8bitsec
sourcehttps://packetstormsecurity.com/files/147363/Blog-Master-Pro-1.0-CSV-Injection.html
titleBlog Master Pro 1.0 CSV Injection