What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in anmari amr users.This issue affects amr users: from n/a through 4.59.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
What the vulnerability does
Improper Neutralization of Formula Elements in a CSV File vulnerability in anmari amr users.This issue affects amr users: from n/a through 4.59.4.
Explanation of Vulnerability in Simple Terms
AMR Users versions up to 4.59.4 contain an integrity vulnerability allowing authenticated users with low privileges to modify data through a network-based attack. The vulnerability requires user interaction and high attack complexity. Impact is limited to data integrity with no confidentiality or availability effects. Scope is changed, meaning the impact may extend beyond the vulnerable component.
What an attacker can do
Modify data or settings in the application through a network request.
Potential impact on your site
Authenticated users could alter application data or configuration, potentially affecting site functionality or other users.
Conditions required to exploit
Attacker must be authenticated with low-level privileges and trick a user into clicking a link or visiting a page.
Key dates
External resources
Related vulnerabilities