xujeff tianti
cpe:2.3:a:tianti_project:tianti:*:*:*:*:*:*:*
- <= 2.3
A CSV injection vulnerability has been identified in Xujeff Tianti versions through 2.3. The issue arises in the 'exportOrder' function within the 'com.jeff.tianti.controller' component, specifically in the file '/tianti-module-admin/user/ajax/save'. This vulnerability allows low-privilege users to inject malicious input that, when the exported CSV file is opened in a spreadsheet application like Microsoft Excel, could execute commands on the user's machine.
Exploitation of this vulnerability could lead to unauthorized command execution on the machine where the manipulated CSV file is opened.
To reproduce this vulnerability, log into the Tianti CMS as a low-privilege user. Inject malicious input, such as spreadsheet formulas starting with '=', into the user list. When the CSV is exported and opened, double-clicking the injected cell will execute the embedded command.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.