CVE-2021-27839
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did…
Does this matter?
Lower severity and a low EPSS score (0.72%). Track it; it rarely justifies an emergency change on its own.
Description
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1236
- Affected
- bigprof/online invoicing system
- Source
- cve@mitre.org
References
- https://github.com/bigprof-software/online-invoicing-system/releases/tag/4.4Release Notes, Third Party Advisory
- https://www.jinsonvarghese.com/csv-injection-in-online-invoicing-system/Third Party Advisory
- https://github.com/bigprof-software/online-invoicing-system/releases/tag/4.4Release Notes, Third Party Advisory
- https://www.jinsonvarghese.com/csv-injection-in-online-invoicing-system/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.