Cyber Posture

CVE-2023-46401

CriticalPublic PoC

Published: 23 January 2025

Published
23 January 2025
Modified
04 February 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0013 31.7th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.

Security Summary

CVE-2023-46401 is a CSV Formula Injection vulnerability in the invoice adding function of KWHotel version 0.47. Published on 2025-01-23, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and is associated with CWE-1236.

The vulnerability can be exploited by any unauthenticated remote attacker over the network, requiring low complexity and no user interaction. Successful exploitation enables high-impact consequences on confidentiality, integrity, and availability.

Mitigation details are available in the referenced advisory at https://gist.github.com/6en6ar/5d39374d6ced8acbe489e0b1b932d056.

Details

CWE(s)
CWE-1236

Affected Products

kwhotel
kwhotel
0.47

References