CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Description
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (305)
page 2 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3188 | Cri | 0.64 | 9.8 | 0.02 | Jan 26, 2021 | phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports. | ||
| CVE-2020-22274 | Cri | 0.64 | 9.8 | 0.02 | Nov 4, 2020 | JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile. | ||
| CVE-2020-22276 | Cri | 0.64 | 9.8 | 0.03 | Nov 4, 2020 | WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. | ||
| CVE-2020-11548 | Cri | 0.64 | 9.8 | 0.05 | Apr 5, 2020 | The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed. | ||
| CVE-2020-7947 | Cri | 0.64 | 9.8 | 0.03 | Apr 1, 2020 | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting… | ||
| CVE-2020-9347 | Cri | 0.64 | 9.8 | 0.08 | Mar 16, 2020 | Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be… | ||
| CVE-2019-0403 | Cri | 0.64 | 9.8 | 0.02 | Dec 11, 2019 | SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection. | ||
| CVE-2019-4521 | Cri | 0.64 | 9.8 | 0.03 | Dec 10, 2019 | Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179. | ||
| CVE-2019-13144 | Cri | 0.64 | 9.8 | 0.02 | Jul 5, 2019 | myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5. | ||
| CVE-2018-20752 | Cri | 0.64 | 9.8 | 0.03 | Feb 4, 2019 | An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not be properly sanitized when exported to a CSV file. This can… | ||
| CVE-2019-19676 | Cri | 0.63 | 9.6 | 0.01 | Mar 18, 2020 | A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains… | ||
| CVE-2018-15474 | Cri | 0.63 | 9.6 | 0.03 | Sep 7, 2018 | CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the… | ||
| CVE-2026-47705 | Cri | 0.62 | 9.6 | 0.00 | Aug 11, 2026 | TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which… | ||
| CVE-2023-47534 | Cri | 0.62 | 9.6 | 0.01 | Mar 12, 2024 | A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted… | ||
| CVE-2019-14749 | Hig | 0.61 | 8.8 | 0.10 | Aug 7, 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields… | ||
| CVE-2018-10258 | Hig | 0.61 | 8.8 | 0.07 | May 1, 2018 | A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | ||
| CVE-2018-10257 | Hig | 0.61 | 8.8 | 0.04 | May 1, 2018 | A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | ||
| CVE-2018-10255 | Hig | 0.61 | 8.8 | 0.07 | May 1, 2018 | A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | ||
| CVE-2018-9107 | Hig | 0.61 | 8.8 | 0.07 | Mar 28, 2018 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export. | ||
| CVE-2018-9106 | Hig | 0.61 | 8.8 | 0.05 | Mar 28, 2018 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export. |
- risk 0.64cvss 9.8epss 0.02
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
- risk 0.64cvss 9.8epss 0.02
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
- risk 0.64cvss 9.8epss 0.03
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
- risk 0.64cvss 9.8epss 0.05
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting…
- risk 0.64cvss 9.8epss 0.08
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be…
- risk 0.64cvss 9.8epss 0.02
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.
- risk 0.64cvss 9.8epss 0.03
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179.
- risk 0.64cvss 9.8epss 0.02
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not be properly sanitized when exported to a CSV file. This can…
- risk 0.63cvss 9.6epss 0.01
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains…
- risk 0.63cvss 9.6epss 0.03
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the…
- risk 0.62cvss 9.6epss 0.00
TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which…
- risk 0.62cvss 9.6epss 0.01
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted…
- risk 0.61cvss 8.8epss 0.10
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields…
- risk 0.61cvss 8.8epss 0.07
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- risk 0.61cvss 8.8epss 0.04
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- risk 0.61cvss 8.8epss 0.07
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- risk 0.61cvss 8.8epss 0.07
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.
- risk 0.61cvss 8.8epss 0.05
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.