CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Description
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (305)
page 4 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-25983 | Hig | 0.57 | 8.8 | 0.01 | Nov 7, 2023 | Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84. | ||
| CVE-2023-4006 | Cri | 0.57 | 9.8 | 0.01 | Jul 31, 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16. | ||
| CVE-2022-28864 | Hig | 0.57 | 8.8 | 0.01 | Jul 24, 2023 | An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim… | ||
| CVE-2023-33410 | Hig | 0.57 | 8.8 | 0.01 | Jun 5, 2023 | Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is used to construct a CSV file. | ||
| CVE-2022-40294 | Hig | 0.57 | 8.8 | 0.01 | Oct 31, 2022 | The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers. | ||
| CVE-2022-1194 | Hig | 0.57 | 8.8 | 0.01 | Sep 16, 2022 | The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability. | ||
| CVE-2022-2240 | Hig | 0.57 | 8.8 | 0.01 | Jul 25, 2022 | The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it | ||
| CVE-2022-1539 | Hig | 0.57 | 8.8 | 0.01 | Jul 25, 2022 | The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. | ||
| CVE-2022-28481 | Cri | 0.57 | 9.8 | 0.02 | May 1, 2022 | CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection. | ||
| CVE-2022-29315 | Hig | 0.57 | 8.8 | 0.01 | Apr 19, 2022 | Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used. | ||
| CVE-2021-39022 | Hig | 0.57 | 8.8 | 0.00 | Mar 10, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet… | ||
| CVE-2022-22689 | Hig | 0.57 | 8.8 | 0.01 | Feb 4, 2022 | CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands. | ||
| CVE-2021-27020 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2021 | Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export. | ||
| CVE-2020-22390 | Hig | 0.57 | 8.8 | 0.02 | Jun 21, 2021 | Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened. | ||
| CVE-2020-4633 | Hig | 0.57 | 8.8 | 0.03 | Dec 11, 2020 | IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation. | ||
| CVE-2020-25398 | Hig | 0.57 | 8.8 | 0.02 | Nov 5, 2020 | CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality. | ||
| CVE-2020-22278 | Hig | 0.57 | 8.8 | 0.02 | Nov 4, 2020 | phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents. | ||
| CVE-2020-22275 | Hig | 0.57 | 8.8 | 0.02 | Nov 4, 2020 | Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable. | ||
| CVE-2020-14026 | Hig | 0.57 | 8.8 | 0.02 | Sep 22, 2020 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export. | ||
| CVE-2020-13826 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2020 | A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export. |
- risk 0.57cvss 8.8epss 0.01
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84.
- risk 0.57cvss 9.8epss 0.01
Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim…
- risk 0.57cvss 8.8epss 0.01
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is used to construct a CSV file.
- risk 0.57cvss 8.8epss 0.01
The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.
- risk 0.57cvss 8.8epss 0.01
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
- risk 0.57cvss 8.8epss 0.01
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
- risk 0.57cvss 8.8epss 0.01
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.
- risk 0.57cvss 9.8epss 0.02
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
- risk 0.57cvss 8.8epss 0.01
Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.
- risk 0.57cvss 8.8epss 0.00
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet…
- risk 0.57cvss 8.8epss 0.01
CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands.
- risk 0.57cvss 8.8epss 0.01
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
- risk 0.57cvss 8.8epss 0.02
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
- risk 0.57cvss 8.8epss 0.03
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
- risk 0.57cvss 8.8epss 0.02
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
- risk 0.57cvss 8.8epss 0.02
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
- risk 0.57cvss 8.8epss 0.02
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.
- risk 0.57cvss 8.8epss 0.02
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.
- risk 0.57cvss 8.8epss 0.01
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.