Vulnerability Description
UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uipath | Orchestrator | < 2018.3.4 |
Related Weaknesses (CWE)
References
- https://www.uipath.com/product/release-notesRelease NotesVendor Advisory
- https://www2.deloitte.com/de/de/pages/risk/articles/uipath-orchestrator-csv-injeExploitThird Party Advisory
- https://www.uipath.com/product/release-notesRelease NotesVendor Advisory
- https://www2.deloitte.com/de/de/pages/risk/articles/uipath-orchestrator-csv-injeExploitThird Party Advisory
FAQ
What is CVE-2018-19855?
CVE-2018-19855 is a vulnerability with a CVSS score of 5.5 (MEDIUM). UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features.
How severe is CVE-2018-19855?
CVE-2018-19855 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19855?
Check the references section above for vendor advisories and patch information. Affected products include: Uipath Orchestrator.