Back

MEDIUM

A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file

Published Sep 3, 2019

Description

A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.

Affected products

Remediation

Vendor solution

Update your LXCA installation to version 2.5.0 or later.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner lenovo
Published Sep 3, 2019
Updated Sep 17, 2024
Reserved Jan 11, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner lenovo
Published Sep 3, 2019
Updated Sep 17, 2024
Exploited since n/a
EUVD-2019-15749