CVE-2024-28111
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 6, 2024
Updated: Mar 7, 2024
CWE ID 1236
Summary
CVE-2024-28111 is a vulnerability in Canarytokens, a tool used to monitor network activity. The issue lies in the generation of CSV files containing Canarytoken incident histories. An attacker who discovers an HTTP-based Canarytoken can exploit this CSV Injection vulnerability if the token owner exports and opens the file in a reader application like Microsoft Excel. The impact is significant, as it could lead to code execution on the affected machine. Canarytokens version sha-c595a1f8 includes a fix for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.