Show plain JSON{"id": "CVE-2020-26507", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 9.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "MEDIUM", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.8}]}, "published": "2020-11-05T18:15:12.583", "references": [{"url": "https://www.marmind.com/en/", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://www2.deloitte.com/de/de/pages/risk/articles/marmind-csv-injection.html", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.marmind.com/en/", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www2.deloitte.com/de/de/pages/risk/articles/marmind-csv-injection.html", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-1236"}]}], "descriptions": [{"lang": "en", "value": "A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the \u201cNotes\u201d functionality in the main screen, an attacker can inject a payload into the \u201cDescription\u201d field under the \u201cInsert To-Do\u201d option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a software such as Microsoft Excel. The attacker could gain remote access to the user\u2019s PC."}, {"lang": "es", "value": "Una vulnerabilidad CSV Injection (tambi\u00e9n se conoce como Formula Injection) en la aplicaci\u00f3n web Marmind con versi\u00f3n 4.1.141.0, permite a usuarios maliciosos conseguir control remoto de otras computadoras. Al proporcionar un c\u00f3digo de f\u00f3rmula en la funcionalidad \"Notes\" en la pantalla principal, un atacante puede inyectar una carga \u00fatil en el campo \"Description\" debajo de la opci\u00f3n \"Insert To-Do\". Otros usuarios pueden descargar estos datos, por ejemplo, un archivo CSV, y ejecutar los comandos maliciosos en su computadora al abrir un archivo con un software como Microsoft Excel. El atacante podr\u00eda conseguir acceso remoto a la PC del usuario"}], "lastModified": "2024-11-21T05:19:55.703", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:marmind:marmind:4.1.141.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49F5DD96-2509-4803-A458-9382C87879AB"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}