Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: python313Packages.dirsearch

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2021-47901
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 3 weeks ago
dirsearch 0.4.1 - CSV Injection

Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the generated CSV report.

Affected products

dirsearch
  • ==0.4.1

Matching in nixpkgs

Package maintainers