VYPR
High severity8.0NVD Advisory· Published Nov 17, 2023· Updated Jun 17, 2026

CVE-2023-48029

CVE-2023-48029

Description

Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Corebos/Corebos2 versions
    cpe:2.3:a:corebos:corebos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:corebos:corebos:*:*:*:*:*:*:*:*range: <=8.0
    • (no CPE)range: <=8.0
  • Corebos/Corebosdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.