Vulnerabilities > CVE-2023-50448 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Activeadmin

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
activeadmin
CWE-1236

Summary

In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times.

Vulnerable Configurations

Part Description Count
Application
Activeadmin
56