Fallos del tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV contém fórmulas (como =cmd|'/c calc'!A1 ou =1+1), aplicativos que abrem o arquivo automaticamente as interpretam e executam, permitindo injeção de código. O risco é alto porque o usuário apenas abre um arquivo aparentemente inofensivo e o aplicativo (Excel, Calc, etc.) executa comandos maliciosos sem aviso adequado.

Ejemplo

Um relatório exportado em CSV com dados de usuários contém um campo começando com '=' que, quando aberto no Excel, executa uma macro ou comando do sistema. Um atacante injeta a fórmula no banco de dados ou upload de arquivo, e qualquer pessoa que baixe e abra o CSV sofre o ataque.

Cómo mitigar

Prefixe campos suspeitos com um caractere neutro (como aspas simples ou espaço) antes de gerar o CSV, ou configure o aplicativo para não interpretar fórmulas automaticamente. Na aplicação, valide e escape qualquer conteúdo que inicie com caracteres de fórmula (=, +, -, @, tabulação).

CVE-2023-53913MEDIUMRukovoditel 3.3.1 CSV Injection via User Account ExportEPSS 0.7%CVE-2025-56267CRITICALA CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplyiEPSS 0.7%CVE-2021-1474MEDIUMCisco Umbrella Link and CSV Formula Injection VulnerabilitiesEPSS 0.7%CVE-2023-0721HIGHMetform Elementor Contact Form Builder <= 3.3.0 - Unauthenticated CSV InjectionEPSS 0.7%CVE-2022-41791MEDIUMWordPress ProfileGrid plugin <= 5.1.6 - Auth. CSV Injection vulnerabilityEPSS 0.7%CVE-2022-46803MEDIUMWordPress Noptin Plugin <= 1.9.5 is vulnerable to CSV InjectionEPSS 0.7%CVE-2022-46802MEDIUMWordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV InjectionEPSS 0.7%CVE-2022-46801MEDIUMWordPress Site Reviews Plugin <= 6.2.0 is vulnerable to CSV InjectionEPSS 0.7%CVE-2023-51311HIGHPHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vuEPSS 0.7%CVE-2023-51319HIGHPHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulEPSS 0.7%CVE-2024-53555HIGHA CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.EPSS 0.7%CVE-2022-45078MEDIUMWordPress User Blocker Plugin <= 1.5.5 is vulnerable to CSV InjectionEPSS 0.7%CVE-2021-1475MEDIUMCisco Umbrella Link and CSV Formula Injection VulnerabilitiesEPSS 0.7%CVE-2022-47442MEDIUMWordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV InjectionEPSS 0.7%CVE-2023-22877HIGHIBM InfoSphere Information Server CSV injectionEPSS 0.7%CVE-2026-31049CRITICALAn issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV regiEPSS 0.7%CVE-2025-4546MEDIUM1Panel-dev MaxKB Knowledge Base Module csv injectionEPSS 0.7%CVE-2023-51336HIGHPHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. ThEPSS 0.6%CVE-2022-4034MEDIUMAppointment Hour Booking <= 1.3.72 - CSV InjectionEPSS 0.6%CVE-2021-38963HIGHIBM Aspera Console CSV injectionEPSS 0.6%