CVE-2022-40294

The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:phppointofsale:php_point_of_sale:19.0:*:*:*:*:*:*:*

History

03 Nov 2022, 02:50

Type Values Removed Values Added
References (MISC) https://www.themissinglink.com.au/security-advisories/cve-2022-40294 - (MISC) https://www.themissinglink.com.au/security-advisories/cve-2022-40294 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-1236
CPE cpe:2.3:a:phppointofsale:php_point_of_sale:19.0:*:*:*:*:*:*:*

31 Oct 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-31 21:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-40294

Mitre link : CVE-2022-40294

CVE.ORG link : CVE-2022-40294


JSON object : View

Products Affected

phppointofsale

  • php_point_of_sale
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File