Show filters
62 Total Results
Displaying 21-30 of 62
Sort by:
Attacker Value
Unknown

CVE-2021-27839

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.
Attacker Value
Unknown

CVE-2021-21302

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2
Attacker Value
Unknown

CVE-2020-9205

Disclosure Date: February 06, 2021 (last updated February 22, 2025)
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
Attacker Value
Unknown

CVE-2021-3188

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
Attacker Value
Unknown

CVE-2020-9200

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
Attacker Value
Unknown

CVE-2019-16959

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
Attacker Value
Unknown

CVE-2020-28861

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.
Attacker Value
Unknown

CVE-2020-4633

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
Attacker Value
Unknown

CVE-2020-4627

Disclosure Date: November 25, 2020 (last updated February 22, 2025)
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
Attacker Value
Unknown

CVE-2020-28845

Disclosure Date: November 20, 2020 (last updated February 22, 2025)
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.