Fallos del tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV contém fórmulas (como =cmd|'/c calc'!A1 ou =1+1), aplicativos que abrem o arquivo automaticamente as interpretam e executam, permitindo injeção de código. O risco é alto porque o usuário apenas abre um arquivo aparentemente inofensivo e o aplicativo (Excel, Calc, etc.) executa comandos maliciosos sem aviso adequado.

Ejemplo

Um relatório exportado em CSV com dados de usuários contém um campo começando com '=' que, quando aberto no Excel, executa uma macro ou comando do sistema. Um atacante injeta a fórmula no banco de dados ou upload de arquivo, e qualquer pessoa que baixe e abra o CSV sofre o ataque.

Cómo mitigar

Prefixe campos suspeitos com um caractere neutro (como aspas simples ou espaço) antes de gerar o CSV, ou configure o aplicativo para não interpretar fórmulas automaticamente. Na aplicação, valide e escape qualquer conteúdo que inicie com caracteres de fórmula (=, +, -, @, tabulação).

CVE-2023-25348HIGHChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new peEPSS 0.4%CVE-2024-27785MEDIUMAn improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenEPSS 0.4%CVE-2026-14846MEDIUMIncorrect neutralisation in the PrestaShop firmwareEPSS 0.4%CVE-2021-23286MEDIUMSecurity issues in Eaton Intelligent Power Manager InfrastructureEPSS 0.4%CVE-2024-45084HIGHIBM Cognos Controller CSV injectionEPSS 0.4%CVE-2024-9102MEDIUMphpLDAPadmin: Improper Neutralization of Formula ElementsEPSS 0.4%CVE-2025-60852MEDIUMA CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versionsEPSS 0.4%CVE-2023-51298MEDIUMPHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulEPSS 0.4%CVE-2023-2629MEDIUMImproper Neutralization of Formula Elements in a CSV File in pimcore/customer-data-frameworkEPSS 0.4%CVE-2021-47901MEDIUMdirsearch 0.4.1 - CSV InjectionEPSS 0.4%CVE-2025-50572HIGHArcher 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be execEPSS 0.4%CVE-2025-62417HIGHbagisto - CSV Formula Injection in Create New ProductEPSS 0.4%CVE-2026-18738MEDIUMShlink CSV Formula Injection via Visit Export CLIEPSS 0.4%CVE-2026-47693MEDIUMPoweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applicationsEPSS 0.4%CVE-2023-46400MEDIUMKWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.EPSS 0.4%CVE-2026-39424MEDIUMMaxKB has CSV Injection in its Application Chat Export FunctionalityEPSS 0.4%CVE-2023-54348HIGHERPGo SaaS 3.9 CSV Injection via Vendor CreationEPSS 0.4%CVE-2025-14229MEDIUMSourceCodester Inventory Management System SVC Report Export csv injectionEPSS 0.4%CVE-2025-39245MEDIUMThere is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands vEPSS 0.3%CVE-2025-11254MEDIUMContest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV InjectionEPSS 0.3%