CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Description
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (305)
page 6 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-51094 | Hig | 0.52 | 8.0 | 0.00 | Nov 12, 2024 | An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the… | ||
| CVE-2021-38963 | Hig | 0.52 | 8.0 | 0.01 | Sep 25, 2024 | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute… | ||
| CVE-2024-24337 | Hig | 0.52 | 8.0 | 0.01 | Feb 12, 2024 | CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components. | ||
| CVE-2023-42004 | Hig | 0.52 | 8.0 | 0.01 | Nov 28, 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262. | ||
| CVE-2023-48029 | Hig | 0.52 | 8.0 | 0.01 | Nov 17, 2023 | Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading… | ||
| CVE-2023-38843 | Hig | 0.52 | 8.0 | 0.01 | Aug 17, 2023 | An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the description field in the incident function. | ||
| CVE-2022-41675 | Hig | 0.52 | 8.0 | 0.01 | Nov 29, 2022 | A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow the attacker to perform arbitrary system operation or… | ||
| CVE-2022-3558 | Hig | 0.52 | 8.0 | 0.01 | Nov 7, 2022 | The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files. | ||
| CVE-2022-40472 | Hig | 0.52 | 8.0 | 0.01 | Sep 29, 2022 | ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message… | ||
| CVE-2022-38844 | Hig | 0.52 | 8.0 | 0.01 | Sep 16, 2022 | CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on… | ||
| CVE-2022-2798 | Hig | 0.52 | 8.0 | 0.01 | Sep 16, 2022 | The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data | ||
| CVE-2020-36503 | Hig | 0.52 | 8.0 | 0.01 | Nov 1, 2021 | The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue | ||
| CVE-2021-24441 | Hig | 0.52 | 8.0 | 0.01 | Jul 12, 2021 | The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue | ||
| CVE-2020-22277 | Hig | 0.52 | 8.0 | 0.02 | Nov 4, 2020 | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. | ||
| CVE-2020-9017 | Hig | 0.52 | 8.0 | 0.01 | Feb 25, 2020 | LiteCart through 2.2.1 allows CSV injection via a customer's profile. | ||
| CVE-2019-4364 | Hig | 0.52 | 8.0 | 0.03 | Jun 19, 2019 | IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680. | ||
| CVE-2024-27321 | Hig | 0.51 | 7.8 | 0.00 | Sep 12, 2024 | An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file… | ||
| CVE-2024-27320 | Hig | 0.51 | 7.8 | 0.00 | Sep 12, 2024 | An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing… | ||
| CVE-2024-41226 | Hig | 0.51 | 7.8 | 0.01 | Aug 6, 2024 | A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack… | ||
| CVE-2022-3604 | Hig | 0.51 | 7.8 | 0.00 | Jan 16, 2024 | The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection. |
- risk 0.52cvss 8.0epss 0.00
An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the…
- risk 0.52cvss 8.0epss 0.01
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute…
- risk 0.52cvss 8.0epss 0.01
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.
- risk 0.52cvss 8.0epss 0.01
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
- risk 0.52cvss 8.0epss 0.01
Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading…
- risk 0.52cvss 8.0epss 0.01
An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the description field in the incident function.
- risk 0.52cvss 8.0epss 0.01
A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow the attacker to perform arbitrary system operation or…
- risk 0.52cvss 8.0epss 0.01
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
- risk 0.52cvss 8.0epss 0.01
ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message…
- risk 0.52cvss 8.0epss 0.01
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on…
- risk 0.52cvss 8.0epss 0.01
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data
- risk 0.52cvss 8.0epss 0.01
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
- risk 0.52cvss 8.0epss 0.01
The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue
- risk 0.52cvss 8.0epss 0.02
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
- risk 0.52cvss 8.0epss 0.01
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
- risk 0.52cvss 8.0epss 0.03
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
- risk 0.51cvss 7.8epss 0.00
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file…
- risk 0.51cvss 7.8epss 0.00
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing…
- risk 0.51cvss 7.8epss 0.01
A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack…
- risk 0.51cvss 7.8epss 0.00
The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.