Vulnerabilities (CVE)

Filtered by CWE-1236
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3026 1 Wp-users-exporter Project 1 Wp-users-exporter 2024-01-11 N/A 8.8 HIGH
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into profile information like First Names that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
CVE-2023-31294 1 Sesami 1 Cash Point \& Transport Optimizer 2024-01-08 N/A 7.5 HIGH
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.
CVE-2023-31295 1 Sesami 1 Cash Point \& Transport Optimizer 2024-01-08 N/A 7.5 HIGH
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.
CVE-2023-48207 1 Phpjabbers 1 Availability Booking Calendar 2023-12-11 N/A 8.8 HIGH
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
CVE-2023-42004 1 Ibm 1 Security Guardium 2023-12-04 N/A 8.8 HIGH
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
CVE-2023-48029 1 Corebos 1 Corebos 2023-11-25 N/A 8.0 HIGH
Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer.
CVE-2023-25983 1 Liquidweb 1 Kb Support 2023-11-15 N/A 8.8 HIGH
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84.
CVE-2022-46804 1 Narolainfotech 1 Export Users Data Distinct 2023-11-14 N/A 8.8 HIGH
Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.
CVE-2023-38843 1 Atlos 1 Atlos 2023-08-23 N/A 8.0 HIGH
An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the description field in the incident function.
CVE-2023-37219 1 Tadirantele 1 Aeonix 2023-08-04 N/A 7.8 HIGH
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CVE-2022-28864 1 Nokia 1 Netact 2023-08-02 N/A 8.8 HIGH
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.
CVE-2022-1539 1 Exports And Reports Project 1 Exports And Reports 2022-07-29 N/A 8.8 HIGH
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.
CVE-2022-2240 1 Emarketdesign 1 Request A Quote 2022-07-29 N/A 8.8 HIGH
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
CVE-2022-2112 1 Inventree 1 Inventree 2022-06-29 6.8 MEDIUM 8.8 HIGH
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
CVE-2022-1202 1 Usabilitydynamics 1 Wp-crm 2022-06-17 6.8 MEDIUM 7.8 HIGH
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
CVE-2022-2027 1 Kromit 1 Titra 2022-06-15 3.5 LOW 8.0 HIGH
Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2020-36531 1 Ibm 1 Sevone Network Performance Management 2022-06-14 6.0 MEDIUM 8.8 HIGH
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely.
CVE-2022-26867 1 Dell 3 Powerstore T, Powerstore X, Powerstoreos 2022-06-13 6.0 MEDIUM 8.0 HIGH
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.
CVE-2021-46363 1 Magnolia-cms 1 Magnolia Cms 2022-06-05 9.3 HIGH 7.8 HIGH
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.
CVE-2022-1544 1 Luya 1 Yii-helpers 2022-05-12 6.8 MEDIUM 7.8 HIGH
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.
CVE-2022-29315 1 Invicti 1 Acunetix 2022-04-27 9.3 HIGH 8.8 HIGH
Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.
CVE-2021-23286 1 Eaton 1 Intelligent Power Manager 2022-04-27 7.9 HIGH 8.0 HIGH
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions.
CVE-2022-22689 1 Broadcom 1 Ca Harvest Software Change Manager 2022-02-10 6.5 MEDIUM 8.8 HIGH
CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands.
CVE-2022-22121 1 Xgenecloud 1 Nocodb 2022-01-19 6.0 MEDIUM 8.0 HIGH
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a CSV file and opens it, the payload gets executed.
CVE-2020-9372 1 Codepeople 1 Appointment Booking Calendar 2022-01-01 6.8 MEDIUM 7.8 HIGH
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
CVE-2021-41824 1 Craftcms 1 Craft Cms 2021-11-30 6.8 MEDIUM 8.8 HIGH
Craft CMS before 3.7.14 allows CSV injection.
CVE-2020-15255 1 Anuko 1 Time Tracker 2021-11-18 6.0 MEDIUM 7.3 HIGH
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.
CVE-2021-38424 1 Deltaww 1 Dialink 2021-11-05 6.8 MEDIUM 7.8 HIGH
The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.
CVE-2021-40848 1 Mahara 1 Mahara 2021-11-05 6.8 MEDIUM 7.8 HIGH
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.
CVE-2020-36503 1 Connections-pro 1 Connections Business Directory 2021-11-03 6.0 MEDIUM 8.0 HIGH
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
CVE-2021-25960 1 Salesagility 1 Suitecrm 2021-10-07 6.0 MEDIUM 8.0 HIGH
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file and opens it, the payload gets executed. This was not fixed properly as part of CVE-2020-15301, allowing the attacker to bypass the security measure.
CVE-2021-25962 1 Shuup 1 Shuup 2021-10-06 6.8 MEDIUM 8.8 HIGH
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed.
CVE-2021-33256 1 Zohocorp 1 Manageengine Adselfservice Plus 2021-09-21 9.3 HIGH 8.8 HIGH
** DISPUTED ** A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side."
CVE-2021-27020 1 Puppet 1 Puppet Enterprise 2021-09-07 6.8 MEDIUM 8.8 HIGH
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
CVE-2021-37702 1 Pimcore 1 Pimcore 2021-08-26 6.5 MEDIUM 8.8 HIGH
Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.
CVE-2021-22771 1 Schneider-electric 2 Easergy T300, Easergy T300 Firmware 2021-07-28 6.0 MEDIUM 7.3 HIGH
A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.
CVE-2020-19513 1 Aida64 1 Aida64 2021-07-21 4.6 MEDIUM 7.8 HIGH
Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a crafted input that will overwrite the SEH handler.
CVE-2020-22390 1 Akaunting 1 Akaunting 2021-06-25 6.8 MEDIUM 8.8 HIGH
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
CVE-2021-22153 1 Blackberry 1 Unified Endpoint Management 2021-05-21 6.0 MEDIUM 7.3 HIGH
A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user.
CVE-2021-29667 2 Ibm, Linux 2 Spectrum Scale, Linux Kernel 2021-05-05 6.8 MEDIUM 7.8 HIGH
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403.
CVE-2021-1474 1 Cisco 1 Umbrella 2021-04-19 6.8 MEDIUM 8.6 HIGH
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVE-2021-21302 1 Prestashop 1 Prestashop 2021-03-04 6.5 MEDIUM 7.2 HIGH
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2
CVE-2020-9200 1 Huawei 1 Imanager Neteco 6000 2020-12-28 7.2 HIGH 7.8 HIGH
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
CVE-2020-28845 1 Netskope 1 Netskope 2020-12-02 9.3 HIGH 7.8 HIGH
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
CVE-2020-15301 1 Salesagility 1 Suitecrm 2020-12-02 6.8 MEDIUM 7.8 HIGH
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
CVE-2020-26507 1 Marmind 1 Marmind 2020-11-19 9.3 HIGH 7.8 HIGH
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “Notes” functionality in the main screen, an attacker can inject a payload into the “Description” field under the “Insert To-Do” option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a software such as Microsoft Excel. The attacker could gain remote access to the user’s PC.
CVE-2019-20184 1 Keepass 1 Keepass 2020-11-17 6.8 MEDIUM 7.8 HIGH
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
CVE-2020-25170 1 Bbraun 1 Onlinesuite Application Package 2020-11-13 6.8 MEDIUM 7.8 HIGH
An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
CVE-2020-22278 1 Phpmyadmin 1 Phpmyadmin 2020-11-13 6.8 MEDIUM 8.8 HIGH
** DISPUTED ** phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents."
CVE-2020-25398 1 Mind 1 Imind Server 2020-11-12 6.8 MEDIUM 8.8 HIGH
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.