Description
A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. The payload is being injected in the http Response from the client-side, so the owner of the Response and payload is the end user in this case. They contend that the server's security controls have no impact or role to play in this situation and therefore this is not a valid vulnerability.
INFO
Published Date :
2024-08-06T00:00:00.000Z
Last Modified :
2024-09-03T21:02:39.796Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2024-41226 vulnerability.
| Vendors | Products |
|---|---|
| Automationanywhere |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-41226.