CVE-2022-21241
08.02.2022, 11:15
Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.
Vendor | Product | Version |
---|---|---|
csv\+_project | csv\+ | 𝑥 < 0.8.1 |
𝑥
= Vulnerable software versions