Home

Description

A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.

PUBLISHED Reserved 2025-08-16 | Published 2025-09-08 | Updated 2025-09-08 | Assigner mitre

References

github.com/nikolas-ch/CVEs/tree/main/AvigilonACM_v7.10.0.20

github.com/...tree/main/AvigilonACM_v7.10.0.20/CSV_Injection

github.com/...ACM_v7.10.0.20/CSV_Injection/CSV_Injection.txt

cve.org (CVE-2025-56267)

nvd.nist.gov (CVE-2025-56267)

Download JSON