CSV Injection Vulnerability in Shopy Point of Sale v1.0 Allows Code Execution

CSV Injection Vulnerability in Shopy Point of Sale v1.0 Allows Code Execution

CVE-2018-10258 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

Learn more about our User Device Pen Test.