CVE-2018-7201: High severity projectsend vulnerability
Published May 22, 2019
·Updated
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
Affected Software
1 affected component
ProjectSend ProjectSend<1053
Event History
May 22, 2019
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this CSV Injection vulnerability?
The vulnerability ID of this CSV Injection vulnerability is CVE-2018-7201.
2
What is the severity of CVE-2018-7201?
The severity of CVE-2018-7201 is high with a CVSS score of 8.8.
3
Which version of ProjectSend is affected by CVE-2018-7201?
CVE-2018-7201 affects ProjectSend version up to (but excluding) r1053.
4
Who is affected by CVE-2018-7201?
Victims who import the data into Microsoft Excel are affected by CVE-2018-7201.
5
Is there a fix available for CVE-2018-7201?
Yes, a fix is available for CVE-2018-7201. Users should update to a version beyond r1053.