9.8

CVE-2024-53924

Exploit
Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DgorissenPycel Version1.0 Updatebeta0 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta11 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta12 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta13 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta14 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta15 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta16 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta17 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta18 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta19 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta2 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta20 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta21 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta22 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta26 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta27 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta28 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta29 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta3 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta30 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta4 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta5 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta6 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta7 SwPlatformpython
DgorissenPycel Version1.0 Updatebeta8 SwPlatformpython
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.61% 0.814
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.