VYPR
Medium severity5.9NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026

CVE-2022-26867

CVE-2022-26867

Description

PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Dell/Powerstoreos2 versions
    cpe:2.3:o:dell:powerstoreos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:dell:powerstoreos:*:*:*:*:*:*:*:*range: <2.1.1.0
    • (no CPE)range: unspecified
  • Range: = 2.1.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.