Total
280 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-4633 | 1 Ibm | 1 Resilient Security Orchestration Automation And Response | 2024-11-21 | 9.0 HIGH | 8.8 HIGH |
|
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
|
|||||
| CVE-2020-4627 | 1 Ibm | 1 Cloud Pak For Security | 2024-11-21 | 9.0 HIGH | 9.0 CRITICAL |
|
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
|
|||||
| CVE-2020-4302 | 1 Ibm | 1 Cognos Analytics | 2024-11-21 | 9.3 HIGH | 7.8 HIGH |
|
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.
|
|||||
| CVE-2020-36531 | 1 Ibm | 1 Sevone Network Performance Management | 2024-11-21 | 6.0 MEDIUM | 6.3 MEDIUM |
|
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely.
|
|||||
| CVE-2020-36503 | 1 Connections-pro | 1 Connections Business Directory | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
|
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
|
|||||
| CVE-2020-28861 | 1 Openasset | 1 Digital Asset Management | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.
|
|||||
| CVE-2020-28845 | 1 Netskope | 1 Netskope | 2024-11-21 | 9.3 HIGH | 7.8 HIGH |
|
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
|
|||||
| CVE-2020-26507 | 1 Marmind | 1 Marmind | 2024-11-21 | 9.3 HIGH | 7.8 HIGH |
|
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “Notes” functionality in the main screen, an attacker can inject a payload into the “Description” field under the “Insert To-Do” option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a sof ...
Show More |
|||||
| CVE-2020-25445 | 1 Bookingcore | 1 Booking Core | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.
|
|||||
| CVE-2020-25398 | 1 Mind | 1 Imind Server | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
|
|||||
| CVE-2020-25170 | 1 Bbraun | 1 Onlinesuite Application Package | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
|
|||||
| CVE-2020-24707 | 1 Getgophish | 1 Gophish | 2024-11-21 | 9.3 HIGH | 7.8 HIGH |
|
Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
|
|||||
| CVE-2020-22390 | 1 Akaunting | 1 Akaunting | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
|
|||||
| CVE-2020-22278 | 1 Phpmyadmin | 1 Phpmyadmin | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
|
|||||
| CVE-2020-22277 | 1 Codection | 1 Import And Export Users And Customers | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
|
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
|
|||||
| CVE-2020-22276 | 1 Weformspro | 1 Weforms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
|
|||||
| CVE-2020-22275 | 1 Easyregistrationforms | 1 Easy Registration Forms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.
|
|||||
| CVE-2020-22274 | 1 Jomsocial | 1 Jomsocial | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
|
|||||
| CVE-2020-15301 | 1 Salesagility | 1 Suitecrm | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
|
|||||
| CVE-2020-15255 | 1 Anuko | 1 Time Tracker | 2024-11-21 | 6.0 MEDIUM | 8.7 HIGH |
|
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.
|
|||||
| CVE-2020-14026 | 1 Ozeki | 1 Ozeki Ng Sms Gateway | 2024-11-21 | 9.3 HIGH | 8.8 HIGH |
|
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.
|
|||||
| CVE-2020-13826 | 1 I-doit | 1 I-doit | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
|
|||||
| CVE-2020-13247 | 1 Boolebox | 1 Boolebox | 2024-11-21 | 8.5 HIGH | 7.3 HIGH |
|
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.
|
|||||
| CVE-2020-13146 | 1 Edx | 1 Open Edx Platform | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
|
|||||
| CVE-2020-11548 | 1 Search Meter Project | 1 Search Meter | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
|
|||||
| CVE-2020-10780 | 1 Redhat | 1 Cloudforms Management Engine | 2024-11-21 | 4.9 MEDIUM | 6.3 MEDIUM |
|
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.
|
|||||
| CVE-2020-10460 | 1 Chadhaajay | 1 Phpkb | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
|
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.
|
|||||
| CVE-2020-10131 | 1 Searchblox | 1 Searchblox | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
|
|||||
| CVE-2019-6187 | 1 Lenovo | 42 Thinksystem Sr670, Thinkagile 7d1h, Thinkagile 7x82 and 39 more | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
|
|||||
| CVE-2019-6182 | 1 Lenovo | 1 Xclarity Administrator | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
|
A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.
|
|||||
| CVE-2019-4521 | 1 Ibm | 1 Cloud Pak System | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179.
|
|||||
| CVE-2019-4364 | 1 Ibm | 10 Control Desk, Maximo Asset Management, Maximo For Aviation and 7 more | 2024-11-21 | 8.5 HIGH | 8.0 HIGH |
|
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
|
|||||
| CVE-2019-4071 | 1 Ibm | 2 Spectrum Control, Tivoli Storage Productivity Center | 2024-11-21 | 9.3 HIGH | 8.8 HIGH |
|
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.
|
|||||
| CVE-2019-20184 | 1 Keepass | 1 Keepass | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
|
|||||
| CVE-2019-20180 | 1 Tablepress | 1 Tablepress | 2024-11-21 | 6.0 MEDIUM | 6.8 MEDIUM |
|
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.
|
|||||
| CVE-2019-20002 | 1 Solarwinds | 1 Webhelpdesk | 2024-11-21 | 6.0 MEDIUM | 7.8 HIGH |
|
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
|
|||||
| CVE-2019-19676 | 1 Arxes-tolina | 1 Arxes-tolina | 2024-11-21 | 9.3 HIGH | 9.6 CRITICAL |
|
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
|
|||||
| CVE-2019-17661 | 1 Admincolumns | 1 Admin Columns | 2024-11-21 | 9.0 HIGH | 8.8 HIGH |
|
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
|
|||||
| CVE-2019-16959 | 1 Solarwinds | 1 Webhelpdesk | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
|
|||||
| CVE-2019-16184 | 1 Limesurvey | 1 Limesurvey | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
|
|||||