Show filters
89 Total Results
Displaying 71-80 of 89
Sort by:
Attacker Value
Unknown

CVE-2020-4302

Disclosure Date: October 09, 2020 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.
Attacker Value
Unknown

CVE-2020-14026

Disclosure Date: September 22, 2020 (last updated February 22, 2025)
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.
Attacker Value
Unknown

CVE-2020-16214

Disclosure Date: September 11, 2020 (last updated February 22, 2025)
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.
Attacker Value
Unknown

CVE-2020-13826

Disclosure Date: August 20, 2020 (last updated February 22, 2025)
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
Attacker Value
Unknown

CVE-2020-10780

Disclosure Date: August 11, 2020 (last updated February 21, 2025)
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.
Attacker Value
Unknown

CVE-2020-7049

Disclosure Date: June 30, 2020 (last updated February 21, 2025)
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
Attacker Value
Unknown

CVE-2020-13247

Disclosure Date: June 24, 2020 (last updated February 21, 2025)
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.
Attacker Value
Unknown

CVE-2020-13146

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
Attacker Value
Unknown

CVE-2019-20002

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
Attacker Value
Unknown

CVE-2020-11548

Disclosure Date: April 05, 2020 (last updated February 21, 2025)
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.