Flamingo <= 2.1 - CSV Injection
mediumA CSV Injection vulnerability was discovered in Flamingo up to version 2.1. It allows a user with low level privileges to inject OS command that will be included in the exported CSV file, leading to possible command/code execution.
- CVSS:
- 6.4
- Affected:
- up to 2.1
- Fixed in:
- 2.1.1
- Disclosed:
- Jan 15, 2020