Weaknesses of type CWE-1236

190 results

Neutralização inadequada de fórmulas em arquivos CSV

Ocorre quando um arquivo CSV exportado contém fórmulas (como =SUM(), @SUM() ou similar) que são interpretadas automaticamente por aplicações como Excel ou LibreOffice. Um atacante injeta fórmulas maliciosas nos dados, que executam comandos ou acessam recursos quando o arquivo é aberto, contornando a percepção do usuário de que está apenas lendo dados.

Example

Uma aplicação web exporta dados de usuários para CSV. Um atacante insere o nome '=cmd|' /c calc'!A1' em seu perfil. Quando um admin abre o CSV no Excel, a fórmula executa a calculadora ou outro comando sem avisar.

How to mitigate

Prefixe dados suspeitos com aspas simples (') ou espaço antes de exportar, ou converta as células para texto puro explicitamente. Alternativamente, use formatos como JSON ou XML e oriente os usuários a abrir CSVs com modo de segurança aumentado ou importadores que não interpretam fórmulas.

CVE-2024-28111MEDIUMCSV Injection in exported history CSV filesEPSS 0.6%CVE-2025-55745LOWUnoPim Quick Export feature is vulnerable to CSV injectionEPSS 0.6%CVE-2022-45810MEDIUMWordPress Email Subscribers & Newsletters Plugin <= 5.5.2 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-22719MEDIUMWordPress GiveWP Plugin <= 2.25.1 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-51302HIGHPHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulneEPSS 0.6%CVE-2022-45360MEDIUMWordPress Commenter Emails Plugin <= 2.6.1 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-23678MEDIUMWordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin <= 2.2.5 is vulnerable to CSV InjectionEPSS 0.6%CVE-2022-38702MEDIUMWordPress WP CSV Exporter Plugin <= 2.0 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-23796MEDIUMWordPress Form Builder Plugin <= 1.9.9.0 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-41798MEDIUMWordPress Directorist Plugin <= 7.7.1 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-36527MEDIUMWordPress Post to CSV by BestWebSoft Plugin <= 1.4.0 is vulnerable to CSV InjectionEPSS 0.6%CVE-2020-16214Philips Patient Monitoring Devices Improper Neutralization of Formula Elements in a CSV FileEPSS 0.6%CVE-2022-26867MEDIUMPowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation oEPSS 0.6%CVE-2022-44830HIGHSourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and EPSS 0.6%CVE-2024-47572HIGHAn improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorizEPSS 0.6%CVE-2026-23873MEDIUMHUSTOJ is Vulnerable to Stored CSV Injection (Formula Injection) in Contest Rank ExportEPSS 0.6%CVE-2023-3527MEDIUMAvaya Call Management System CSV injection vulnerabilityEPSS 0.6%CVE-2024-41226HIGHA CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted pEPSS 0.6%CVE-2023-47295CRITICALA CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload EPSS 0.6%CVE-2024-47485MEDIUMThere is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to geneEPSS 0.6%