CSV File Injection Vulnerability in VMware AirWatch Console 9.x

CSV File Injection Vulnerability in VMware AirWatch Console 9.x

CVE-2017-4931 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files. Successful exploitation of this issue could result in an unsuspecting AWC user opening a CSV file which contains malicious content.

Learn more about our User Device Pen Test.