GRANDING UTime Master - CSV Injection
Hi All,
I was able to identify CSV Injection Vulnerability in one online attendance system i.e. GRANDING UTime Master (v UTime Master_9.0.7-Build:Apr 4,2023).
UTime Master is a powerful web-based time and attendance management software that provides a stable connection to GRANDING’s standalone push communication devices by Ethernet/Wi-Fi/GPRS/3G and working as a private cloud to offer employee self-service by mobile application and web browser.
- Login to UTime Master using admin account
- Click on Personnel > Employee Management >Employee
- Select Any employee or create a new employee
- In First name Section embed you payload. For test case I used " =cmd|' /C notepad'!'A1' "
CSV payload embed in EMP NAME field.
Once submitted, the CSV payload will be visible in First Name Field. Click on export button and click on CSV Export.
Comments
Post a Comment