CVE-2019-6187: Lenovo Xclarity Controller
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Affected products
- Lenovo Xclarity Controller: before tei392m (fixed in tei392m); before cdi340m (fixed in cdi340m); before g1i312 (fixed in g1i312); before psi328m (fixed in psi328m)
Published 2019-11-20. Last modified 2026-06-17.