VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 16 of 16
  • CVE-2022-22121HigJan 10, 2022
    risk 0.00cvss 8.0epss 0.01

    In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a…

  • CVE-2021-25960HigSep 29, 2021
    risk 0.00cvss 8.0epss 0.01

    In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access…

  • CVE-2021-37702HigAug 18, 2021
    risk 0.00cvss 8.0epss 0.01

    Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.

  • CVE-2021-21302MedFeb 26, 2021
    risk 0.00cvss 6.8epss 0.01

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2

  • CVE-2020-24707HigOct 28, 2020
    risk 0.00cvss 7.8epss 0.01

    Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.