CVE-2022-29315: Critical severity invicti acunetix vulnerability
Published Apr 19, 2022
·Updated
Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.
Affected Software
1 affected component
Invicti Acunetix<14
Event History
Apr 19, 2022
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29315?
CVE-2022-29315 has a medium severity rating due to its potential for CSV injection leading to possible execution of arbitrary commands.
2
How do I fix CVE-2022-29315?
To fix CVE-2022-29315, upgrade to Invicti Acunetix version 14 or later where the vulnerability is resolved.
3
What is the impact of CVE-2022-29315?
The impact of CVE-2022-29315 includes unauthorized actions executed by opening a maliciously crafted CSV file.
4
Who is affected by CVE-2022-29315?
Users of Invicti Acunetix versions prior to 14 are affected by CVE-2022-29315.
5
What features are involved in CVE-2022-29315?
CVE-2022-29315 involves the Description field on the Add Targets page and the Export CSV feature.