VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (317)

page 7 of 16
  • CVE-2020-9017HigFeb 25, 2020
    risk 0.52cvss 8.0epss 0.01

    LiteCart through 2.2.1 allows CSV injection via a customer's profile.

  • CVE-2019-4364HigJun 19, 2019
    risk 0.52cvss 8.0epss 0.03

    IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.

  • CVE-2026-9852HigSep 3, 2026
    risk 0.51cvss 7.8epss 0.00

    A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To…

  • CVE-2024-27321HigSep 12, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file…

  • CVE-2024-27320HigSep 12, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing…

  • CVE-2024-41226HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.01

    A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack…

  • CVE-2022-3604HigJan 16, 2024
    risk 0.51cvss 7.8epss 0.00

    The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

  • CVE-2023-25348HigApr 25, 2023
    risk 0.51cvss 7.8epss 0.00

    ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

  • CVE-2022-44830HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

  • CVE-2022-1202HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.01

    The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.

  • CVE-2022-23868HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.01

    RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.

  • CVE-2021-46363HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.

  • CVE-2021-40848HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.01

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

  • CVE-2020-25445HigJul 14, 2021
    risk 0.51cvss 7.8epss 0.01

    The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells…

  • CVE-2021-29667HigApr 27, 2021
    risk 0.51cvss 7.8epss 0.01

    IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403.

  • CVE-2021-24144HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.01

    Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.

  • CVE-2020-9200HigDec 24, 2020
    risk 0.51cvss 7.8epss 0.00

    There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can…

  • CVE-2020-28845HigNov 20, 2020
    risk 0.51cvss 7.8epss 0.01

    A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.

  • CVE-2020-15301HigNov 18, 2020
    risk 0.51cvss 7.8epss 0.01

    SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.

  • CVE-2020-4759HigNov 9, 2020
    risk 0.51cvss 7.8epss 0.02

    IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736.