Vulnerabilities > CVE-2018-10258 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Codeslab Shopy Point of Sale 1.0

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
codeslab
CWE-1236
exploit available

Summary

A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

Vulnerable Configurations

Part Description Count
Application
Codeslab
1

Exploit-Db

descriptionShopy Point of Sale 1.0 - CSV Injection. CVE-2018-10258. Webapps exploit for PHP platform
fileexploits/php/webapps/44534.txt
idEDB-ID:44534
last seen2018-05-24
modified2018-04-25
platformphp
port
published2018-04-25
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44534/
titleShopy Point of Sale 1.0 - CSV Injection
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/147362/shopypos10-inject.txt
idPACKETSTORM:147362
last seen2018-04-27
published2018-04-26
reporter8bitsec
sourcehttps://packetstormsecurity.com/files/147362/Shopy-Point-Of-Sale-1.0-CSV-Injection.html
titleShopy Point Of Sale 1.0 CSV Injection