ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-25445”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-25445
Published
2021-07-14
CVSS:
7.8
ShadowTrackr CVSS:
4.0
Summary:
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.