mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-01 11:11:27 +00:00
24 lines
1.0 KiB
JSON
24 lines
1.0 KiB
JSON
{
|
|
"id": "CVE-2024-24337",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2024-02-12T22:15:08.430",
|
|
"lastModified": "2024-02-13T14:01:49.147",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Vulnerabilidad de inyecci\u00f3n CSV en los endpoints '/members/moremember.pl' y '/admin/aqbudgets.pl' en Koha Library Management System versi\u00f3n 23.05.05 y anteriores permite a los atacantes inyectar comandos DDE en exportaciones csv a trav\u00e9s de los componentes 'Budget' y 'Patrons Member'."
|
|
}
|
|
],
|
|
"metrics": {},
|
|
"references": [
|
|
{
|
|
"url": "https://nitipoom-jar.github.io/CVE-2024-24337/",
|
|
"source": "cve@mitre.org"
|
|
}
|
|
]
|
|
} |