Falhas do tipo CWE-1236
178 resultadosFalta de neutralização de fórmulas em arquivos CSV
Quando um arquivo CSV é gerado com dados não sanitizados, fórmulas de planilhas (Excel, LibreOffice) podem ser injetadas. Ao abrir o arquivo, a aplicação executa a fórmula automaticamente, permitindo execução arbitrária de código ou acesso a dados sensíveis do usuário.
Exemplo
Um sistema exporta um relatório CSV com dados de clientes. Um atacante injeta no banco de dados o valor '=cmd|'/c calc'!A1', que fica no CSV. Quando um analista abre em Excel, a calculadora é executada no computador dele.
Como mitigar
Prefixe células suspeitas com aspas ou espaço (='' + formula) antes de exportar, ou use formatos seguros como ODS/XLSX com validação de fórmulas. Oriente usuários a desabilitar execução automática de macros em imports.
CVE-2020-36962MEDIUMTendenci 12.3.1 - CSV/ Formula InjectionEPSS 10.7%CVE-2022-0142—Visual Form Builder < 3.0.6 - CSV InjectionEPSS 2.7%CVE-2022-1544HIGHFormula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in luyadev/yii-helpersEPSS 2.4%CVE-2019-17661HIGHA CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control EPSS 2.4%CVE-2023-29918MEDIUMRosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.EPSS 2.2%CVE-2021-38180—SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitatiEPSS 2.1%CVE-2024-29375CRITICALCSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to tEPSS 1.5%CVE-2022-1539—Exports and Reports < 0.9.2 - Contributor+ CSV InjectionEPSS 1.5%CVE-2022-2240—Request a Quote <= 2.3.7 - CSV InjectionEPSS 1.4%CVE-2021-41270MEDIUMCSV Injection in SymfonyEPSS 1.4%CVE-2022-3574CRITICALWPForms Pro < 1.7.7 - CSV InjectionEPSS 1.3%CVE-2021-24441—Sign-up Sheets < 1.0.14 - Authenticated CSV InjectionEPSS 1.3%CVE-2022-24770HIGHImproper Neutralization of Formula Elements in a CSV File in Gradio FlaggingEPSS 1.3%CVE-2022-3393CRITICALPost to CSV by BestWebSoft <= 1.4.0 - Author+ CSV InjectionEPSS 1.3%CVE-2022-22689—CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, dueEPSS 1.3%CVE-2022-3463CRITICALFluentForm < 4.3.13 - CSV InjectionEPSS 1.2%CVE-2022-22121HIGHNocoDB - CSV Injection in User ManagementEPSS 1.2%CVE-2022-2112CRITICALImproper Neutralization of Formula Elements in a CSV File in inventree/inventreeEPSS 1.2%CVE-2020-36503—Connections Business Directory < 9.7 - Admin+ CSV InjectionEPSS 1.2%CVE-2021-25960HIGHSuiteCRM - CSV Injection in Accounts ModuleEPSS 1.2%