Fallos del tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV contém fórmulas (como =cmd|'/c calc'!A1 ou =1+1), aplicativos que abrem o arquivo automaticamente as interpretam e executam, permitindo injeção de código. O risco é alto porque o usuário apenas abre um arquivo aparentemente inofensivo e o aplicativo (Excel, Calc, etc.) executa comandos maliciosos sem aviso adequado.

Ejemplo

Um relatório exportado em CSV com dados de usuários contém um campo começando com '=' que, quando aberto no Excel, executa uma macro ou comando do sistema. Um atacante injeta a fórmula no banco de dados ou upload de arquivo, e qualquer pessoa que baixe e abra o CSV sofre o ataque.

Cómo mitigar

Prefixe campos suspeitos com um caractere neutro (como aspas simples ou espaço) antes de gerar o CSV, ou configure o aplicativo para não interpretar fórmulas automaticamente. Na aplicação, valide e escape qualquer conteúdo que inicie com caracteres de fórmula (=, +, -, @, tabulação).

CVE-2022-37786MEDIUMAn issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / EPSS 0.5%CVE-2023-53929MEDIUMphpMyFAQ 3.1.12 CSV Injection via User Profile ExportEPSS 0.5%CVE-2023-3493HIGHImproper Neutralization of Formula Elements in a CSV File in fossbilling/fossbillingEPSS 0.5%CVE-2020-36941MEDIUMKnockpy 4.1.1 - CSV InjectionEPSS 0.5%CVE-2021-38424MEDIUMDelta Electronics DIALinkEPSS 0.5%CVE-2022-35281MEDIUMIBM Maximo Application Suite command injectionEPSS 0.5%CVE-2023-28958HIGHIBM Watson Knowledge Catalog CSV injectionEPSS 0.5%CVE-2023-53905MEDIUMProjectSend r1605 CSV Injection via User Account Export FunctionalityEPSS 0.5%CVE-2023-5424MEDIUMWS Form LITE <= 1.9.217 - Unauthenticated CSV InjectionEPSS 0.5%CVE-2023-5527HIGHBusiness Directory Plugin <= 6.4.3 - Authenticated (Author+) CSV InjectionEPSS 0.5%CVE-2023-46401HIGHKWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.EPSS 0.5%CVE-2026-47705CRITICALTypeBot vulnerable to CSV injection in result exportEPSS 0.5%CVE-2024-3232HIGHFormula Injection VulnerabilityEPSS 0.5%CVE-2024-53260MEDIUMCourse Roster vulnerable to CSV Injection in AutolabEPSS 0.5%CVE-2026-19501HIGHCVE-2026-19501EPSS 0.5%CVE-2023-3302MEDIUMImproper Neutralization of Formula Elements in a CSV File in admidio/admidioEPSS 0.5%CVE-2026-86745MEDIUMSnipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping ExportEPSS 0.4%CVE-2023-45597MEDIUMA CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web apEPSS 0.4%CVE-2024-25007HIGHEricsson Network Manager - Improper Neutralization of Formula Elements VulnerabilityEPSS 0.4%CVE-2024-51094HIGHAn issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into EPSS 0.4%