GHSA-p9qj-4rjp-j3w9
HIGHCVE-2015-5349The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
- Affected
- < 2.0.0.v20151221-M10
- Fixed in
- 2.0.0.v20151221-M10
- Weakness
- CWE-77
- Published
- 2022-05-13
- Source
- github