What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5.
Explanation of Vulnerability in Simple Terms
User Blocker through version 1.5.5 contains a vulnerability that allows an authenticated administrator to perform actions affecting other users' data. The vulnerability requires the administrator to interact with a malicious link or page. The impact is limited to low-level disclosure, modification, and availability issues.
What an attacker can do
An authenticated admin can view, modify, or disrupt other users' data by tricking them into clicking a link.
Potential impact on your site
An admin account could be manipulated to leak or alter user data or cause service disruption.
Conditions required to exploit
Attacker must have admin privileges and the victim admin must click a malicious link.
Key dates
External resources
Related vulnerabilities