CVE-2023-31296
MEDIUM WAF: Medium
CVSS 5.3
Published: 2023-12-29
CWE-94
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.
WAF Coverage Analysis
Code Injection
Medium WAF Coverage
OWASP: A03:2021 Injection
932xxx - Remote Code Execution 933xxx - PHP Injection 934xxx - Node.js / Generic Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| sesami | cash_point_\&_transport_optimizer | 6.3.8.6.718 |
References
- herolab.usd.de (Third Party Advisory)