Vulnerability Description
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet software.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nokia | Impact Mobile | >= 19.11, <= 23 |
Related Weaknesses (CWE)
References
- https://nokia.comProduct
- https://www.gruppotim.it/it/footer/red-team/2023/Motive-Impact-CVE-2023-31044.htThird Party Advisory
FAQ
What is CVE-2023-31044?
CVE-2023-31044 is a vulnerability with a CVSS score of 2.0 (LOW). An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the C...
How severe is CVE-2023-31044?
CVE-2023-31044 has been rated LOW with a CVSS base score of 2.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31044?
Check the references section above for vendor advisories and patch information. Affected products include: Nokia Impact Mobile.