Impact
By filling malicious code in a CSV content, an XSS attack can be performed when importing this content.
Patches
Fixed in 3.1.3, 3.2.1
Workarounds
Check CSV content before importing it
References
Credits
Huge thanks to @aditinnara for reporting this.
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com
Impact
By filling malicious code in a CSV content, an XSS attack can be performed when importing this content.
Patches
Fixed in 3.1.3, 3.2.1
Workarounds
Check CSV content before importing it
References
Credits
Huge thanks to @aditinnara for reporting this.
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com