VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 2 of 16
  • CVE-2021-3188CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.02

    phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.

  • CVE-2020-22274CriNov 4, 2020
    risk 0.64cvss 9.8epss 0.02

    JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.

  • CVE-2020-22276CriNov 4, 2020
    risk 0.64cvss 9.8epss 0.03

    WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.

  • CVE-2020-11548CriApr 5, 2020
    risk 0.64cvss 9.8epss 0.05

    The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

  • CVE-2020-7947CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting…

  • CVE-2020-9347CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.08

    Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be…

  • CVE-2019-0403CriDec 11, 2019
    risk 0.64cvss 9.8epss 0.02

    SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.

  • CVE-2019-4521CriDec 10, 2019
    risk 0.64cvss 9.8epss 0.03

    Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179.

  • CVE-2019-13144CriJul 5, 2019
    risk 0.64cvss 9.8epss 0.02

    myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.

  • CVE-2018-20752CriFeb 4, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not be properly sanitized when exported to a CSV file. This can…

  • CVE-2019-19676CriMar 18, 2020
    risk 0.63cvss 9.6epss 0.01

    A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains…

  • CVE-2018-15474CriSep 7, 2018
    risk 0.63cvss 9.6epss 0.03

    CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the…

  • CVE-2026-47705CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.00

    TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which…

  • CVE-2023-47534CriMar 12, 2024
    risk 0.62cvss 9.6epss 0.01

    A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted…

  • CVE-2019-14749HigAug 7, 2019
    risk 0.61cvss 8.8epss 0.10

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields…

  • CVE-2018-10258HigMay 1, 2018
    risk 0.61cvss 8.8epss 0.07

    A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

  • CVE-2018-10257HigMay 1, 2018
    risk 0.61cvss 8.8epss 0.04

    A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

  • CVE-2018-10255HigMay 1, 2018
    risk 0.61cvss 8.8epss 0.07

    A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

  • CVE-2018-9107HigMar 28, 2018
    risk 0.61cvss 8.8epss 0.07

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.

  • CVE-2018-9106HigMar 28, 2018
    risk 0.61cvss 8.8epss 0.05

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.