Weaknesses of type CWE-1236

190 results

Neutralização inadequada de fórmulas em arquivos CSV

Ocorre quando um arquivo CSV exportado contém fórmulas (como =SUM(), @SUM() ou similar) que são interpretadas automaticamente por aplicações como Excel ou LibreOffice. Um atacante injeta fórmulas maliciosas nos dados, que executam comandos ou acessam recursos quando o arquivo é aberto, contornando a percepção do usuário de que está apenas lendo dados.

Example

Uma aplicação web exporta dados de usuários para CSV. Um atacante insere o nome '=cmd|' /c calc'!A1' em seu perfil. Quando um admin abre o CSV no Excel, a fórmula executa a calculadora ou outro comando sem avisar.

How to mitigate

Prefixe dados suspeitos com aspas simples (') ou espaço antes de exportar, ou converta as células para texto puro explicitamente. Alternativamente, use formatos como JSON ou XML e oriente os usuários a abrir CSVs com modo de segurança aumentado ou importadores que não interpretam fórmulas.

CVE-2022-22121HIGHNocoDB - CSV Injection in User ManagementEPSS 1.2%CVE-2022-2798Affiliates Manager < 2.9.14 - Affiliate CSV InjectionEPSS 1.2%CVE-2021-25960HIGHSuiteCRM - CSV Injection in Accounts ModuleEPSS 1.2%CVE-2022-2027HIGHImproper Neutralization of Formula Elements in a CSV File in kromitgmbh/titraEPSS 1.2%CVE-2023-33410HIGHMinical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists dEPSS 1.2%CVE-2022-22425CRITICAL"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on thEPSS 1.2%CVE-2021-22771A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older thEPSS 1.1%CVE-2023-25983HIGHWordPress KB Support Plugin <= 1.5.84 is vulnerable to CSV InjectionEPSS 1.1%CVE-2022-3558HIGHImport and export users and customers < 1.20.5 - Subscriber+ CSV InjectionEPSS 1.1%CVE-2021-25962HIGHShuup - Formula Injection in Checkout AddressesEPSS 1.1%CVE-2023-42004HIGHIBM Security Guardium CSV injectionEPSS 1.1%CVE-2021-37702HIGHImproper Neutralization of Formula Elements in a CSV File in pimcore/pimcoreEPSS 1.1%CVE-2023-47534HIGHA improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.EPSS 1.1%CVE-2022-1202WP-CRM <= 1.2.1 - CSV InjectionEPSS 1.0%CVE-2020-25170B. Braun OnlineSuiteEPSS 1.0%CVE-2022-40472HIGHZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vuEPSS 1.0%CVE-2023-48709HIGHiTop vulnerable to potential formula injection in Excel/CSV export fileEPSS 1.0%CVE-2023-2258HIGHImproper Neutralization of Formula Elements in a CSV File in alfio-event/alf.ioEPSS 0.9%CVE-2022-41675HIGHTEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server - Formula InjectionEPSS 0.9%CVE-2022-27858HIGHWordPress Activity Log plugin <= 2.8.3 - CSV Injection vulnerabilityEPSS 0.9%