CVE-2023-33410

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jun 5, 2023
Updated: Jan 8, 2025
CWE ID 1236

Summary

CVE-2023-33410 is a newly identified vulnerability affecting Minical version 1.0.0 and earlier. This issue permits attackers to inject malicious code into CSV files through insufficient input validation on the Customer Name field in the Accounting module. Successful exploitation of this CSV injection vulnerability could lead to remote code execution, posing a significant risk to affected systems. Organizations using Minical are urged to apply the necessary patches or upgrades as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share