Weaknesses of type CWE-1236

190 results

Neutralização inadequada de fórmulas em arquivos CSV

Ocorre quando um arquivo CSV exportado contém fórmulas (como =SUM(), @SUM() ou similar) que são interpretadas automaticamente por aplicações como Excel ou LibreOffice. Um atacante injeta fórmulas maliciosas nos dados, que executam comandos ou acessam recursos quando o arquivo é aberto, contornando a percepção do usuário de que está apenas lendo dados.

Example

Uma aplicação web exporta dados de usuários para CSV. Um atacante insere o nome '=cmd|' /c calc'!A1' em seu perfil. Quando um admin abre o CSV no Excel, a fórmula executa a calculadora ou outro comando sem avisar.

How to mitigate

Prefixe dados suspeitos com aspas simples (') ou espaço antes de exportar, ou converta as células para texto puro explicitamente. Alternativamente, use formatos como JSON ou XML e oriente os usuários a abrir CSVs com modo de segurança aumentado ou importadores que não interpretam fórmulas.

CVE-2022-45357MEDIUMWordPress 1003 Mortgage Application Plugin <= 1.75 is vulnerable to CSV InjectionEPSS 0.9%CVE-2022-45370MEDIUMWordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-45350LOWWordPress Simple History Plugin <= 3.3.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2023-51333HIGHPHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnEPSS 0.8%CVE-2022-44738MEDIUMWordPress Posts and Users Stats Plugin <= 1.1.3 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-41616HIGHWordPress Export Users Data CSV Plugin <= 2.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2024-24337HIGHCSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.EPSS 0.8%CVE-2023-4006HIGHImproper Neutralization of Formula Elements in a CSV File in thorsten/phpmyfaqEPSS 0.8%CVE-2024-22063HIGHZTE ZENIC ONE R58 product has a CSV injection vulnerabilityEPSS 0.8%CVE-2022-37905MEDIUMVulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequenEPSS 0.8%CVE-2022-46804MEDIUMWordPress Export Users Data Distinct Plugin <= 1.3 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-40294HIGHCSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLCEPSS 0.8%CVE-2024-55532CRITICALApache Ranger: Improper Neutralization of Formula Elements in a CSV FileEPSS 0.8%CVE-2022-46809MEDIUMWordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-42882MEDIUMWordPress Simple CSV/XLS Exporter Plugin <= 1.5.8 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-45348MEDIUMWordPress amr users Plugin <= 4.59.4 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-46821MEDIUMWordPress Emails & Newsletters with Jackmail Plugin <= 1.2.22 is vulnerable to CSV InjectionEPSS 0.8%CVE-2023-35899HIGHIBM Cloud Pak for Automation CSV injectionEPSS 0.8%CVE-2024-3214MEDIUMRelevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV InjectionEPSS 0.8%CVE-2022-38061MEDIUMWordPress Export Post Info plugin <= 1.2.0 - Authenticated CSV Injection vulnerabilityEPSS 0.7%