- Description
- A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232
- Source
- vulnreport@tenable.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 7.6
- Impact score
- 6
- Exploitability score
- 1
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
- Severity
- HIGH
- vulnreport@tenable.com
- CWE-1236
- Hype score
- Not currently trending