CVE-2024-34448

Ghost before 5.82.0 allows CSV Injection during a member CSV export.
Configurations

No configuration.

History

21 Nov 2024, 09:18

Type Values Removed Values Added
References () https://github.com/phulelouch/CVEs/blob/main/CVE-2024-34448.md - () https://github.com/phulelouch/CVEs/blob/main/CVE-2024-34448.md -

07 Aug 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-74
Summary
  • (es) Ghost anterior a 5.82.0 permite la inyección de CSV durante la exportación de CSV de un miembro.

22 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-22 16:15

Updated : 2024-11-21 09:18


NVD link : CVE-2024-34448

Mitre link : CVE-2024-34448

CVE.ORG link : CVE-2024-34448


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')