Weaknesses of type CWE-1236

190 results

Neutralização inadequada de fórmulas em arquivos CSV

Ocorre quando um arquivo CSV exportado contém fórmulas (como =SUM(), @SUM() ou similar) que são interpretadas automaticamente por aplicações como Excel ou LibreOffice. Um atacante injeta fórmulas maliciosas nos dados, que executam comandos ou acessam recursos quando o arquivo é aberto, contornando a percepção do usuário de que está apenas lendo dados.

Example

Uma aplicação web exporta dados de usuários para CSV. Um atacante insere o nome '=cmd|' /c calc'!A1' em seu perfil. Quando um admin abre o CSV no Excel, a fórmula executa a calculadora ou outro comando sem avisar.

How to mitigate

Prefixe dados suspeitos com aspas simples (') ou espaço antes de exportar, ou converta as células para texto puro explicitamente. Alternativamente, use formatos como JSON ou XML e oriente os usuários a abrir CSVs com modo de segurança aumentado ou importadores que não interpretam fórmulas.

CVE-2022-37786MEDIUMAn issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / EPSS 0.5%CVE-2023-53929MEDIUMphpMyFAQ 3.1.12 CSV Injection via User Profile ExportEPSS 0.5%CVE-2023-3493HIGHImproper Neutralization of Formula Elements in a CSV File in fossbilling/fossbillingEPSS 0.5%CVE-2020-36941MEDIUMKnockpy 4.1.1 - CSV InjectionEPSS 0.5%CVE-2021-38424MEDIUMDelta Electronics DIALinkEPSS 0.5%CVE-2022-35281MEDIUMIBM Maximo Application Suite command injectionEPSS 0.5%CVE-2023-28958HIGHIBM Watson Knowledge Catalog CSV injectionEPSS 0.5%CVE-2023-53905MEDIUMProjectSend r1605 CSV Injection via User Account Export FunctionalityEPSS 0.5%CVE-2023-5424MEDIUMWS Form LITE <= 1.9.217 - Unauthenticated CSV InjectionEPSS 0.5%CVE-2023-5527HIGHBusiness Directory Plugin <= 6.4.3 - Authenticated (Author+) CSV InjectionEPSS 0.5%CVE-2023-46401HIGHKWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.EPSS 0.5%CVE-2026-47705CRITICALTypeBot vulnerable to CSV injection in result exportEPSS 0.5%CVE-2024-3232HIGHFormula Injection VulnerabilityEPSS 0.5%CVE-2024-53260MEDIUMCourse Roster vulnerable to CSV Injection in AutolabEPSS 0.5%CVE-2026-19501HIGHCVE-2026-19501EPSS 0.5%CVE-2023-3302MEDIUMImproper Neutralization of Formula Elements in a CSV File in admidio/admidioEPSS 0.5%CVE-2026-86745MEDIUMSnipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping ExportEPSS 0.4%CVE-2023-45597MEDIUMA CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web apEPSS 0.4%CVE-2024-25007HIGHEricsson Network Manager - Improper Neutralization of Formula Elements VulnerabilityEPSS 0.4%CVE-2024-51094HIGHAn issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into EPSS 0.4%