Weaknesses of type CWE-1236

190 results

Neutralização inadequada de fórmulas em arquivos CSV

Ocorre quando um arquivo CSV exportado contém fórmulas (como =SUM(), @SUM() ou similar) que são interpretadas automaticamente por aplicações como Excel ou LibreOffice. Um atacante injeta fórmulas maliciosas nos dados, que executam comandos ou acessam recursos quando o arquivo é aberto, contornando a percepção do usuário de que está apenas lendo dados.

Example

Uma aplicação web exporta dados de usuários para CSV. Um atacante insere o nome '=cmd|' /c calc'!A1' em seu perfil. Quando um admin abre o CSV no Excel, a fórmula executa a calculadora ou outro comando sem avisar.

How to mitigate

Prefixe dados suspeitos com aspas simples (') ou espaço antes de exportar, ou converta as células para texto puro explicitamente. Alternativamente, use formatos como JSON ou XML e oriente os usuários a abrir CSVs com modo de segurança aumentado ou importadores que não interpretam fórmulas.

CVE-2023-25348HIGHChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new peEPSS 0.4%CVE-2024-27785MEDIUMAn improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenEPSS 0.4%CVE-2026-14846MEDIUMIncorrect neutralisation in the PrestaShop firmwareEPSS 0.4%CVE-2021-23286MEDIUMSecurity issues in Eaton Intelligent Power Manager InfrastructureEPSS 0.4%CVE-2024-45084HIGHIBM Cognos Controller CSV injectionEPSS 0.4%CVE-2024-9102MEDIUMphpLDAPadmin: Improper Neutralization of Formula ElementsEPSS 0.4%CVE-2025-60852MEDIUMA CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versionsEPSS 0.4%CVE-2023-51298MEDIUMPHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulEPSS 0.4%CVE-2023-2629MEDIUMImproper Neutralization of Formula Elements in a CSV File in pimcore/customer-data-frameworkEPSS 0.4%CVE-2021-47901MEDIUMdirsearch 0.4.1 - CSV InjectionEPSS 0.4%CVE-2025-50572HIGHArcher 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be execEPSS 0.4%CVE-2025-62417HIGHbagisto - CSV Formula Injection in Create New ProductEPSS 0.4%CVE-2026-18738MEDIUMShlink CSV Formula Injection via Visit Export CLIEPSS 0.4%CVE-2026-47693MEDIUMPoweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applicationsEPSS 0.4%CVE-2023-46400MEDIUMKWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.EPSS 0.4%CVE-2026-39424MEDIUMMaxKB has CSV Injection in its Application Chat Export FunctionalityEPSS 0.4%CVE-2023-54348HIGHERPGo SaaS 3.9 CSV Injection via Vendor CreationEPSS 0.4%CVE-2025-14229MEDIUMSourceCodester Inventory Management System SVC Report Export csv injectionEPSS 0.4%CVE-2025-39245MEDIUMThere is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands vEPSS 0.3%CVE-2025-11254MEDIUMContest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV InjectionEPSS 0.3%