Vulnerabilities (CVE)

Filtered by CWE-1236
Total 213 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-22277 1 Codection 1 Import And Export Users And Customers 2023-11-07 6.0 MEDIUM 8.0 HIGH
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
CVE-2020-10131 1 Searchblox 1 Searchblox 2023-11-07 N/A 9.8 CRITICAL
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
CVE-2019-20184 1 Keepass 1 Keepass 2023-11-07 6.8 MEDIUM 7.8 HIGH
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
CVE-2019-20002 1 Solarwinds 1 Webhelpdesk 2023-11-07 6.0 MEDIUM 7.8 HIGH
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
CVE-2023-38843 1 Atlos 1 Atlos 2023-08-23 N/A 8.0 HIGH
An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the description field in the incident function.
CVE-2023-37219 1 Tadirantele 1 Aeonix 2023-08-04 N/A 7.8 HIGH
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CVE-2023-4006 1 Phpmyfaq 1 Phpmyfaq 2023-08-03 N/A 9.8 CRITICAL
Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
CVE-2022-28864 1 Nokia 1 Netact 2023-08-02 N/A 8.8 HIGH
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.
CVE-2023-3527 1 Avaya 1 Call Management System 2023-07-28 N/A 6.8 MEDIUM
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software such as Microsoft Excel.  
CVE-2023-28958 1 Ibm 1 Watson Knowledge Catalog On Cloud Pak For Data 2023-07-13 N/A 7.8 HIGH
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
CVE-2023-3493 1 Fossbilling 1 Fossbilling 2023-07-06 N/A 8.0 HIGH
Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.
CVE-2022-46408 1 Ericsson 1 Network Manager 2023-07-06 N/A 6.8 MEDIUM
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected hyperlinks. The attacker would need admin/elevated access to exploit the vulnerability.
CVE-2023-3302 1 Admidio 1 Admidio 2023-06-29 N/A 7.8 HIGH
Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.
CVE-2023-31867 1 Sage 1 X3 2023-06-28 N/A 7.2 HIGH
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
CVE-2023-2629 1 Pimcore 1 Customer Management Framework 2023-05-31 N/A 7.8 HIGH
Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.
CVE-2023-2258 1 Alf 1 Alf 2023-05-03 N/A 8.8 HIGH
Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
CVE-2023-29109 1 Sap 4 Abap Platform, Application Interface Framework, Basis and 1 more 2023-04-18 N/A 4.6 MEDIUM
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application.
CVE-2022-2112 1 Inventree Project 1 Inventree 2023-02-28 6.8 MEDIUM 8.8 HIGH
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
CVE-2019-11872 1 Incsub 1 Hustle 2023-02-24 6.8 MEDIUM 8.8 HIGH
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.
CVE-2019-4364 1 Ibm 10 Control Desk, Maximo Asset Management, Maximo For Aviation and 7 more 2023-01-30 8.5 HIGH 8.0 HIGH
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.