A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2019/Dec/33 | third party advisory mailing list |
https://www.themissinglink.com.au/security-advisories-cve-2019-13181 | third party advisory |
http://packetstormsecurity.com/files/155673/Serv-U-FTP-Server-15.1.7-CSV-Injection.html | vdb entry third party advisory |