RSS   Vulnerabilities for 'Worfklow'   RSS

2019-07-28
 
CVE-2019-14352

CWE-20
 

 
** DISPUTED ** In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the vendor disputes the relevance of this finding because CSV is not the intended export format for spreadsheet applications.

 

 >>> Vendor: Joget 2 Products
Worfklow
Joget dx


Copyright 2024, cxsecurity.com

 

Back to Top