CVE-2024-3232

Published Jul 16, 2024

Last updated 4 months ago

Overview

Description
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232
Source
vulnreport@tenable.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.6
Impact score
6
Exploitability score
1
Vector string
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

vulnreport@tenable.com
CWE-1236

Social media

Hype score
Not currently trending