VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 4 of 16
  • CVE-2023-25983HigNov 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84.

  • CVE-2023-4006CriJul 31, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.

  • CVE-2022-28864HigJul 24, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim…

  • CVE-2023-33410HigJun 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is used to construct a CSV file.

  • CVE-2022-40294HigOct 31, 2022
    risk 0.57cvss 8.8epss 0.01

    The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.

  • CVE-2022-1194HigSep 16, 2022
    risk 0.57cvss 8.8epss 0.01

    The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.

  • CVE-2022-2240HigJul 25, 2022
    risk 0.57cvss 8.8epss 0.01

    The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it

  • CVE-2022-1539HigJul 25, 2022
    risk 0.57cvss 8.8epss 0.01

    The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

  • CVE-2022-28481CriMay 1, 2022
    risk 0.57cvss 9.8epss 0.02

    CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.

  • CVE-2022-29315HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.

  • CVE-2021-39022HigMar 10, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet…

  • CVE-2022-22689HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.01

    CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands.

  • CVE-2021-27020HigAug 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.

  • CVE-2020-22390HigJun 21, 2021
    risk 0.57cvss 8.8epss 0.02

    Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.

  • CVE-2020-4633HigDec 11, 2020
    risk 0.57cvss 8.8epss 0.03

    IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.

  • CVE-2020-25398HigNov 5, 2020
    risk 0.57cvss 8.8epss 0.02

    CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.

  • CVE-2020-22278HigNov 4, 2020
    risk 0.57cvss 8.8epss 0.02

    phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

  • CVE-2020-22275HigNov 4, 2020
    risk 0.57cvss 8.8epss 0.02

    Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.

  • CVE-2020-14026HigSep 22, 2020
    risk 0.57cvss 8.8epss 0.02

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.

  • CVE-2020-13826HigAug 20, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.