Fallos del tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV contém fórmulas (como =cmd|'/c calc'!A1 ou =1+1), aplicativos que abrem o arquivo automaticamente as interpretam e executam, permitindo injeção de código. O risco é alto porque o usuário apenas abre um arquivo aparentemente inofensivo e o aplicativo (Excel, Calc, etc.) executa comandos maliciosos sem aviso adequado.

Ejemplo

Um relatório exportado em CSV com dados de usuários contém um campo começando com '=' que, quando aberto no Excel, executa uma macro ou comando do sistema. Um atacante injeta a fórmula no banco de dados ou upload de arquivo, e qualquer pessoa que baixe e abra o CSV sofre o ataque.

Cómo mitigar

Prefixe campos suspeitos com um caractere neutro (como aspas simples ou espaço) antes de gerar o CSV, ou configure o aplicativo para não interpretar fórmulas automaticamente. Na aplicação, valide e escape qualquer conteúdo que inicie com caracteres de fórmula (=, +, -, @, tabulação).

CVE-2022-22121HIGHNocoDB - CSV Injection in User ManagementEPSS 1.2%CVE-2022-2798Affiliates Manager < 2.9.14 - Affiliate CSV InjectionEPSS 1.2%CVE-2021-25960HIGHSuiteCRM - CSV Injection in Accounts ModuleEPSS 1.2%CVE-2022-2027HIGHImproper Neutralization of Formula Elements in a CSV File in kromitgmbh/titraEPSS 1.2%CVE-2023-33410HIGHMinical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists dEPSS 1.2%CVE-2022-22425CRITICAL"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on thEPSS 1.2%CVE-2021-22771A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older thEPSS 1.1%CVE-2023-25983HIGHWordPress KB Support Plugin <= 1.5.84 is vulnerable to CSV InjectionEPSS 1.1%CVE-2022-3558HIGHImport and export users and customers < 1.20.5 - Subscriber+ CSV InjectionEPSS 1.1%CVE-2021-25962HIGHShuup - Formula Injection in Checkout AddressesEPSS 1.1%CVE-2023-42004HIGHIBM Security Guardium CSV injectionEPSS 1.1%CVE-2021-37702HIGHImproper Neutralization of Formula Elements in a CSV File in pimcore/pimcoreEPSS 1.1%CVE-2023-47534HIGHA improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.EPSS 1.1%CVE-2022-1202WP-CRM <= 1.2.1 - CSV InjectionEPSS 1.0%CVE-2020-25170B. Braun OnlineSuiteEPSS 1.0%CVE-2022-40472HIGHZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vuEPSS 1.0%CVE-2023-48709HIGHiTop vulnerable to potential formula injection in Excel/CSV export fileEPSS 1.0%CVE-2023-2258HIGHImproper Neutralization of Formula Elements in a CSV File in alfio-event/alf.ioEPSS 0.9%CVE-2022-41675HIGHTEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server - Formula InjectionEPSS 0.9%CVE-2022-27858HIGHWordPress Activity Log plugin <= 2.8.3 - CSV Injection vulnerabilityEPSS 0.9%