In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.
2020-09-11T13:15:11.160
2024-11-21T05:06:57.083
Modified
CVSSv3.1: 5.0 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | philips | patient_information_center_ix | b.02 | Yes |
Application | philips | patient_information_center_ix | c.02 | Yes |
Application | philips | patient_information_center_ix | c.03 | Yes |