CVE-2023-31044: Code Injection
An issue was discovered in Nokia Impact before Mobile 23FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31044?
CVE-2023-31044 has a moderate severity level due to its potential for remote code execution via payload injection.
How do I fix CVE-2023-31044?
To fix CVE-2023-31044, upgrade to Nokia Impact Mobile version 23_FP1 or later to ensure the vulnerability is resolved.
Who is affected by CVE-2023-31044?
CVE-2023-31044 affects users of Nokia Impact and Impact DM versions prior to Mobile 23_FP1.
What type of vulnerability is CVE-2023-31044?
CVE-2023-31044 is a remote code execution vulnerability due to improper handling of input in the Campaign Name field.
Can CVE-2023-31044 be exploited without user authentication?
No, exploiting CVE-2023-31044 requires a remote authenticated user to take action using the Add Campaign functionality.