VYPR
Unrated severityNVD Advisory· Published Dec 17, 2025· Updated Apr 7, 2026

Rukovoditel 3.3.1 CSV Injection via User Account Export

CVE-2023-53913

Description

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.