Fallos del tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV contém fórmulas (como =cmd|'/c calc'!A1 ou =1+1), aplicativos que abrem o arquivo automaticamente as interpretam e executam, permitindo injeção de código. O risco é alto porque o usuário apenas abre um arquivo aparentemente inofensivo e o aplicativo (Excel, Calc, etc.) executa comandos maliciosos sem aviso adequado.

Ejemplo

Um relatório exportado em CSV com dados de usuários contém um campo começando com '=' que, quando aberto no Excel, executa uma macro ou comando do sistema. Um atacante injeta a fórmula no banco de dados ou upload de arquivo, e qualquer pessoa que baixe e abra o CSV sofre o ataque.

Cómo mitigar

Prefixe campos suspeitos com um caractere neutro (como aspas simples ou espaço) antes de gerar o CSV, ou configure o aplicativo para não interpretar fórmulas automaticamente. Na aplicação, valide e escape qualquer conteúdo que inicie com caracteres de fórmula (=, +, -, @, tabulação).

CVE-2022-45357MEDIUMWordPress 1003 Mortgage Application Plugin <= 1.75 is vulnerable to CSV InjectionEPSS 0.9%CVE-2022-45370MEDIUMWordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-45350LOWWordPress Simple History Plugin <= 3.3.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2023-51333HIGHPHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnEPSS 0.8%CVE-2022-44738MEDIUMWordPress Posts and Users Stats Plugin <= 1.1.3 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-41616HIGHWordPress Export Users Data CSV Plugin <= 2.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2024-24337HIGHCSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.EPSS 0.8%CVE-2023-4006HIGHImproper Neutralization of Formula Elements in a CSV File in thorsten/phpmyfaqEPSS 0.8%CVE-2024-22063HIGHZTE ZENIC ONE R58 product has a CSV injection vulnerabilityEPSS 0.8%CVE-2022-37905MEDIUMVulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequenEPSS 0.8%CVE-2022-46804MEDIUMWordPress Export Users Data Distinct Plugin <= 1.3 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-40294HIGHCSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLCEPSS 0.8%CVE-2024-55532CRITICALApache Ranger: Improper Neutralization of Formula Elements in a CSV FileEPSS 0.8%CVE-2022-46809MEDIUMWordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-42882MEDIUMWordPress Simple CSV/XLS Exporter Plugin <= 1.5.8 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-45348MEDIUMWordPress amr users Plugin <= 4.59.4 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-46821MEDIUMWordPress Emails & Newsletters with Jackmail Plugin <= 1.2.22 is vulnerable to CSV InjectionEPSS 0.8%CVE-2023-35899HIGHIBM Cloud Pak for Automation CSV injectionEPSS 0.8%CVE-2024-3214MEDIUMRelevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV InjectionEPSS 0.8%CVE-2022-38061MEDIUMWordPress Export Post Info plugin <= 1.2.0 - Authenticated CSV Injection vulnerabilityEPSS 0.7%