CVE-2018-19855

UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features.
Configurations

Configuration 1 (hide)

cpe:2.3:a:uipath:orchestrator:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:58

Type Values Removed Values Added
References () https://www.uipath.com/product/release-notes - Release Notes, Vendor Advisory () https://www.uipath.com/product/release-notes - Release Notes, Vendor Advisory
References () https://www2.deloitte.com/de/de/pages/risk/articles/uipath-orchestrator-csv-injection.html - Exploit, Third Party Advisory () https://www2.deloitte.com/de/de/pages/risk/articles/uipath-orchestrator-csv-injection.html - Exploit, Third Party Advisory

Information

Published : 2019-08-08 13:15

Updated : 2024-11-21 03:58


NVD link : CVE-2018-19855

Mitre link : CVE-2018-19855

CVE.ORG link : CVE-2018-19855


JSON object : View

Products Affected

uipath

  • orchestrator
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File