CVE-2023-46401
CriticalPublic PoC
Published: 23 January 2025
Published
23 January 2025
Modified
04 February 2025
KEV Added
—
Patch
—
CVSS Score
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.0013
31.7th percentile
Risk Priority
20
60% EPSS · 20% KEV · 20% CVSS
Description
KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.
Security Summary
CVE-2023-46401 is a CSV Formula Injection vulnerability in the invoice adding function of KWHotel version 0.47. Published on 2025-01-23, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and is associated with CWE-1236.
The vulnerability can be exploited by any unauthenticated remote attacker over the network, requiring low complexity and no user interaction. Successful exploitation enables high-impact consequences on confidentiality, integrity, and availability.
Mitigation details are available in the referenced advisory at https://gist.github.com/6en6ar/5d39374d6ced8acbe489e0b1b932d056.
Details
- CWE(s)
Affected Products
kwhotel
kwhotel
0.47