Loading HuntDB...

GHSA-3v5g-248q-q8gh

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.

Related CVEs

Key Information

GHSA ID
GHSA-3v5g-248q-q8gh
Published
May 24, 2022 4:55 PM
Last Modified
October 14, 2022 12:00 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.