CVE-2023-31044 LOW

CVE-2023-31044

Vendor N/A
Product n/a
Published March 3, 2026
Last update March 4, 2026

CVSS base score

2.0/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AC:H/AV:N/A:N/C:L/I:N/PR:H/S:U/UI:R

What the vulnerability does

01Description

An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet software.

Key dates

02Disclosure timeline

March 3, 2026 CVE published
March 4, 2026 Record updated