VYPR
High severity8.8NVD Advisory· Published Jun 6, 2019· Updated Jun 17, 2026

CVE-2019-12134

CVE-2019-12134

Description

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Workday/Workday2 versions
    cpe:2.3:a:workday:workday:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:workday:workday:*:*:*:*:*:*:*:*range: <=32.0
    • (no CPE)range: <=32
  • Workday/Workdaydescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.