MidnightBSD

Advisories for codeslab

CVE-2018-10258 MEDIUM

A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-1236,

Products Affected

Vendor Product Version
codeslab shopy_point_of_sale 1.0