Total
155 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-13247 | 1 Boolebox | 1 Boolebox | 2021-07-21 | 8.5 HIGH | 7.3 HIGH |
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area. | |||||
CVE-2020-13826 | 1 I-doit | 1 I-doit | 2021-07-21 | 6.8 MEDIUM | 8.8 HIGH |
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export. | |||||
CVE-2020-22275 | 1 Easyregistrationforms | 1 Easy Registration Forms | 2021-07-21 | 6.8 MEDIUM | 8.8 HIGH |
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable. | |||||
CVE-2020-4302 | 1 Ibm | 1 Cognos Analytics | 2021-07-21 | 9.3 HIGH | 7.8 HIGH |
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610. | |||||
CVE-2020-4633 | 1 Ibm | 1 Resilient Security Orchestration Automation And Response | 2021-07-21 | 9.0 HIGH | 8.8 HIGH |
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation. | |||||
CVE-2020-4627 | 1 Ibm | 1 Cloud Pak For Security | 2021-07-21 | 9.0 HIGH | 9.0 CRITICAL |
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367. | |||||
CVE-2020-4689 | 1 Ibm | 1 Security Guardium | 2021-07-21 | 8.5 HIGH | 6.8 MEDIUM |
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696. | |||||
CVE-2020-7049 | 1 Nozominetworks | 1 Guardian | 2021-07-21 | 8.5 HIGH | 7.3 HIGH |
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection. | |||||
CVE-2020-7947 | 1 Auth0 | 1 Login By Auth0 | 2021-07-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded. | |||||
CVE-2020-9017 | 1 Litecart | 1 Litecart | 2021-07-21 | 6.0 MEDIUM | 8.0 HIGH |
LiteCart through 2.2.1 allows CSV injection via a customer's profile. | |||||
CVE-2020-9466 | 1 Export Users To Csv Project | 1 Export Users To Csv | 2021-07-21 | 5.8 MEDIUM | 6.1 MEDIUM |
The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection. | |||||
CVE-2020-25445 | 1 Bookingcore | 1 Booking Core | 2021-07-16 | 6.8 MEDIUM | 7.8 HIGH |
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed. | |||||
CVE-2021-24441 | 1 Fetchdesigns | 1 Sign-up Sheets | 2021-07-15 | 6.0 MEDIUM | 8.0 HIGH |
The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue | |||||
CVE-2020-22390 | 1 Akaunting | 1 Akaunting | 2021-06-24 | 6.8 MEDIUM | 8.8 HIGH |
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened. | |||||
CVE-2021-22153 | 1 Blackberry | 1 Unified Endpoint Management | 2021-05-21 | 6.0 MEDIUM | 7.3 HIGH |
A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user. | |||||
CVE-2021-29667 | 2 Ibm, Linux | 2 Spectrum Scale, Linux Kernel | 2021-05-05 | 6.8 MEDIUM | 7.8 HIGH |
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403. | |||||
CVE-2021-1475 | 1 Cisco | 1 Umbrella | 2021-04-20 | 3.5 LOW | 4.1 MEDIUM |
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |||||
CVE-2021-1474 | 1 Cisco | 1 Umbrella | 2021-04-19 | 6.8 MEDIUM | 8.6 HIGH |
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |||||
CVE-2021-27839 | 1 Bigprof | 1 Online Invoicing System | 2021-03-10 | 5.8 MEDIUM | 4.4 MEDIUM |
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to. | |||||
CVE-2021-21302 | 1 Prestashop | 1 Prestashop | 2021-03-04 | 6.5 MEDIUM | 7.2 HIGH |
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2 |