CVE-2023-48029
Status: ModifiedHigh (8)—
Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Base score: 8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.29%
- Percentile among all scored CVEs: 69
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-1236
References
- https://gist.github.com/bugplorer/09d312373066a3b72996ebd76a7a23a5
- https://nitipoom-jar.github.io/CVE-2023-48029/
- https://nitipoom-jaroonchaipipat.github.io/security-research-portal/2023-48029
- https://gist.github.com/bugplorer/09d312373066a3b72996ebd76a7a23a5
- https://nitipoom-jar.github.io/CVE-2023-48029/
Raw JSON (NVD)
Show
{
"id": "CVE-2023-48029",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-48029",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-29T17:28:57.594790Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2023-11-17T13:15:09.143",
"references": [
{
"url": "https://gist.github.com/bugplorer/09d312373066a3b72996ebd76a7a23a5",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "https://nitipoom-jar.github.io/CVE-2023-48029/",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://nitipoom-jaroonchaipipat.github.io/security-research-portal/2023-48029",
"source": "cve@mitre.org"
},
{
"url": "https://gist.github.com/bugplorer/09d312373066a3b72996ebd76a7a23a5",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://nitipoom-jar.github.io/CVE-2023-48029/",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-1236"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer."
},
{
"lang": "es",
"value": "Corebos 8.0 y versiones anteriores son vulnerables a la inyección CSV. Un atacante con pocos privilegios puede inyectar un comando malicioso en una tabla. Esta vulnerabilidad se explota cuando un administrador visita la sección de administración de usuarios, exporta los datos a un archivo CSV y luego lo abre, lo que lleva a la ejecución de la carga maliciosa en la maquina del administrador."
}
],
"lastModified": "2026-06-17T06:33:33.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:corebos:corebos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B1C4D90-E645-45EF-94DE-81CF50EF2729",
"versionEndIncluding": "8.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}