CSV injection in Avaya Call Management System (CMS). CVE-2023-3527
Hi All,
I was able to identify CVS injection vulnerability in Avaya Call Management System (CMS). Avaya Call Management System (CMS) is an integrated analysis and reporting solution that keeps you in touch with virtually everything that’s going on in your contact center from evaluating the performance of a single agent or group of agents to managing a contact center with multiple locations worldwide.
During the security assessment of CMS Supervisor Web application, i noted that whole section of "Administration" has a feature to download the content in CSV format. Any malicious user can inject malicious CSV payload, which will be executed if the admin downloads the csv report and opens it.
Affected product: CMS Supervisor Web R19
CMS server release: cms-R19.2.0.2-Lgd.i
CMS web client release: cmsweb-R19.2.0.2-web19gd.i
Build Version: 19.2.0 2789
Build Time: 10/19/2021, 11:55:09 PM
Product: | Vulnerable Version(s): | Resolution: | Information: |
---|---|---|---|
Avaya CMS | R19.x.x.x | Upgrade to 20.0.0.0 or later | Call Management System 20.0.x downloads |
Comments
Post a Comment