Show filters
108 Total Results
Displaying 101-108 of 108
Sort by:
Attacker Value
Unknown
CVE-2019-19676
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
0
Attacker Value
Unknown
CVE-2020-9347
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products
0
Attacker Value
Unknown
CVE-2020-10460
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.
0
Attacker Value
Unknown
CVE-2020-9372
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
0
Attacker Value
Unknown
CVE-2020-9466
Disclosure Date: February 28, 2020 (last updated February 21, 2025)
The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.
0
Attacker Value
Unknown
CVE-2020-9017
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
0
Attacker Value
Unknown
CVE-2019-20180
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.
0
Attacker Value
Unknown
CVE-2019-20184
Disclosure Date: June 19, 2019 (last updated February 21, 2025)
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
0