Show filters
108 Total Results
Displaying 101-108 of 108
Sort by:
Attacker Value
Unknown

CVE-2019-19676

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
Attacker Value
Unknown

CVE-2020-9347

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products
Attacker Value
Unknown

CVE-2020-10460

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.
Attacker Value
Unknown

CVE-2020-9372

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
Attacker Value
Unknown

CVE-2020-9466

Disclosure Date: February 28, 2020 (last updated February 21, 2025)
The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.
Attacker Value
Unknown

CVE-2020-9017

Disclosure Date: February 25, 2020 (last updated February 21, 2025)
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
Attacker Value
Unknown

CVE-2019-20180

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.
Attacker Value
Unknown

CVE-2019-20184

Disclosure Date: June 19, 2019 (last updated February 21, 2025)
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.