Fallos del tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV contém fórmulas (como =cmd|'/c calc'!A1 ou =1+1), aplicativos que abrem o arquivo automaticamente as interpretam e executam, permitindo injeção de código. O risco é alto porque o usuário apenas abre um arquivo aparentemente inofensivo e o aplicativo (Excel, Calc, etc.) executa comandos maliciosos sem aviso adequado.

Ejemplo

Um relatório exportado em CSV com dados de usuários contém um campo começando com '=' que, quando aberto no Excel, executa uma macro ou comando do sistema. Um atacante injeta a fórmula no banco de dados ou upload de arquivo, e qualquer pessoa que baixe e abra o CSV sofre o ataque.

Cómo mitigar

Prefixe campos suspeitos com um caractere neutro (como aspas simples ou espaço) antes de gerar o CSV, ou configure o aplicativo para não interpretar fórmulas automaticamente. Na aplicação, valide e escape qualquer conteúdo que inicie com caracteres de fórmula (=, +, -, @, tabulação).

CVE-2025-67851MEDIUMMoodle: moodle: formula injection allows arbitrary formula execution via unescaped data exportEPSS 0.3%CVE-2023-25611MEDIUMA improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 EPSS 0.3%CVE-2026-76797MEDIUMMongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated ReportsEPSS 0.3%CVE-2026-10248MEDIUMSourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supplier csv injectionEPSS 0.2%CVE-2024-28764MEDIUMIBM WebSphere Automation CSV injectionEPSS 0.2%CVE-2025-54752MEDIUMMultiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victiEPSS 0.2%CVE-2025-52386MEDIUMCycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON fileEPSS 0.2%CVE-2025-1421LOWFormula injection in a CSV file in Proget MDMEPSS 0.2%CVE-2025-35033MEDIUMMedical Informatics Engineering Enterprise Health CSV injectionEPSS 0.2%CVE-2025-58855HIGHWordPress AP HoneyPot WordPress Plugin Plugin <= 1.4 - Cross Site Request Forgery (CSRF) VulnerabilityEPSS 0.2%CVE-2026-55452MEDIUMSnipe-IT: CSV formula injection in Activity Report exportEPSS 0.2%CVE-2026-24447MEDIUMIf a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When EPSS 0.2%CVE-2026-27644MEDIUMtraccar allows CSV formula injection via exported position dataEPSS 0.2%CVE-2025-6838MEDIUMBroken Link Notifier <= 1.3.0 - Authenticated (Contributor+) CSV InjectionEPSS 0.2%CVE-2023-37219HIGH Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV FileEPSS 0.2%CVE-2025-11279MEDIUMAxosoft Scrum and Bug Tracking Add Work Item csv injectionEPSS 0.2%CVE-2025-61873LOWBest Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.EPSS 0.2%CVE-2026-64955MEDIUMVelociraptor CSV Formula Injection in Export PipelineEPSS 0.2%CVE-2026-42267MEDIUMKimai: Formula Injection via tag names in XLSX exportEPSS 0.2%CVE-2026-79971MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper SanitizaEPSS 0.2%