Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-43257

Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.7%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.0
Products affected by CVE-2021-43257


Contact Us

Shodan ® - All rights reserved