Vulnerabilities > CVE-2020-13247 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Boolebox

047910
CVSS 7.3 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
boolebox
CWE-1236

Summary

BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.

Vulnerable Configurations

Part Description Count
Application
Boolebox
1