Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Unknown

CVE-2020-9200

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
Attacker Value
Unknown

CVE-2019-16959

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
Attacker Value
Unknown

CVE-2020-28861

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.
Attacker Value
Unknown

CVE-2020-4633

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
Attacker Value
Unknown

CVE-2020-4627

Disclosure Date: November 25, 2020 (last updated February 22, 2025)
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
Attacker Value
Unknown

CVE-2020-28845

Disclosure Date: November 20, 2020 (last updated February 22, 2025)
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
Attacker Value
Unknown

CVE-2020-15301

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
Attacker Value
Unknown

CVE-2020-4759

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736.
Attacker Value
Unknown

CVE-2020-26507

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “Notes” functionality in the main screen, an attacker can inject a payload into the “Description” field under the “Insert To-Do” option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a software such as Microsoft Excel. The attacker could gain remote access to the user’s PC.
Attacker Value
Unknown

CVE-2020-25398

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.