CSV injection vulnerability in SolarWinds Serv-U

Discovered by Richard Tan on behalf of The Missing Link Security

Vulnerability Details

SolarWinds Serv-U FTP Server allowed table entries to contain a string which could be evaluated by Excel as a Dynamic Data Exchange (DDE) macro. Privileged users who has the appropriate rights to modify or create users could insert values into user properties which is evaluated as macros if the user list is exported as an Excel format.

Affected Versions

Discovered in: 15.1.7

Fixed Versions

Serv-U 15.1.7 Hotfix 2

