Weaknesses of type CWE-1236

190 results

Neutralização inadequada de fórmulas em arquivos CSV

Ocorre quando um arquivo CSV exportado contém fórmulas (como =SUM(), @SUM() ou similar) que são interpretadas automaticamente por aplicações como Excel ou LibreOffice. Um atacante injeta fórmulas maliciosas nos dados, que executam comandos ou acessam recursos quando o arquivo é aberto, contornando a percepção do usuário de que está apenas lendo dados.

Example

Uma aplicação web exporta dados de usuários para CSV. Um atacante insere o nome '=cmd|' /c calc'!A1' em seu perfil. Quando um admin abre o CSV no Excel, a fórmula executa a calculadora ou outro comando sem avisar.

How to mitigate

Prefixe dados suspeitos com aspas simples (') ou espaço antes de exportar, ou converta as células para texto puro explicitamente. Alternativamente, use formatos como JSON ou XML e oriente os usuários a abrir CSVs com modo de segurança aumentado ou importadores que não interpretam fórmulas.

CVE-2023-53913MEDIUMRukovoditel 3.3.1 CSV Injection via User Account ExportEPSS 0.7%CVE-2025-56267CRITICALA CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplyiEPSS 0.7%CVE-2021-1474MEDIUMCisco Umbrella Link and CSV Formula Injection VulnerabilitiesEPSS 0.7%CVE-2023-0721HIGHMetform Elementor Contact Form Builder <= 3.3.0 - Unauthenticated CSV InjectionEPSS 0.7%CVE-2022-41791MEDIUMWordPress ProfileGrid plugin <= 5.1.6 - Auth. CSV Injection vulnerabilityEPSS 0.7%CVE-2022-46803MEDIUMWordPress Noptin Plugin <= 1.9.5 is vulnerable to CSV InjectionEPSS 0.7%CVE-2022-46802MEDIUMWordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV InjectionEPSS 0.7%CVE-2022-46801MEDIUMWordPress Site Reviews Plugin <= 6.2.0 is vulnerable to CSV InjectionEPSS 0.7%CVE-2023-51311HIGHPHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vuEPSS 0.7%CVE-2023-51319HIGHPHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulEPSS 0.7%CVE-2024-53555HIGHA CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.EPSS 0.7%CVE-2022-45078MEDIUMWordPress User Blocker Plugin <= 1.5.5 is vulnerable to CSV InjectionEPSS 0.7%CVE-2021-1475MEDIUMCisco Umbrella Link and CSV Formula Injection VulnerabilitiesEPSS 0.7%CVE-2022-47442MEDIUMWordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV InjectionEPSS 0.7%CVE-2023-22877HIGHIBM InfoSphere Information Server CSV injectionEPSS 0.7%CVE-2026-31049CRITICALAn issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV regiEPSS 0.7%CVE-2025-4546MEDIUM1Panel-dev MaxKB Knowledge Base Module csv injectionEPSS 0.7%CVE-2023-51336HIGHPHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. ThEPSS 0.6%CVE-2022-4034MEDIUMAppointment Hour Booking <= 1.3.72 - CSV InjectionEPSS 0.6%CVE-2021-38963HIGHIBM Aspera Console CSV injectionEPSS 0.6%