Show filters
105 Total Results
Displaying 91-100 of 105
Sort by:
Attacker Value
Unknown
CVE-2020-10780
Disclosure Date: August 11, 2020 (last updated February 21, 2025)
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.
0
Attacker Value
Unknown
CVE-2020-7049
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
0
Attacker Value
Unknown
CVE-2020-13247
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.
0
Attacker Value
Unknown
CVE-2020-13146
Disclosure Date: May 18, 2020 (last updated February 21, 2025)
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
0
Attacker Value
Unknown
CVE-2019-20002
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
0
Attacker Value
Unknown
CVE-2020-11548
Disclosure Date: April 05, 2020 (last updated February 21, 2025)
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
0
Attacker Value
Unknown
CVE-2020-7947
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.
0
Attacker Value
Unknown
CVE-2019-19676
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
0
Attacker Value
Unknown
CVE-2020-9347
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products
0
Attacker Value
Unknown
CVE-2020-10460
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.
0