Falhas do tipo CWE-1236
190 resultadosFalta de neutralização de fórmulas em arquivos CSV
Quando um arquivo CSV é gerado com dados não sanitizados, fórmulas de planilhas (Excel, LibreOffice) podem ser injetadas. Ao abrir o arquivo, a aplicação executa a fórmula automaticamente, permitindo execução arbitrária de código ou acesso a dados sensíveis do usuário.
Exemplo
Um sistema exporta um relatório CSV com dados de clientes. Um atacante injeta no banco de dados o valor '=cmd|'/c calc'!A1', que fica no CSV. Quando um analista abre em Excel, a calculadora é executada no computador dele.
Como mitigar
Prefixe células suspeitas com aspas ou espaço (='' + formula) antes de exportar, ou use formatos seguros como ODS/XLSX com validação de fórmulas. Oriente usuários a desabilitar execução automática de macros em imports.
CVE-2022-45357MEDIUMWordPress 1003 Mortgage Application Plugin <= 1.75 is vulnerable to CSV InjectionEPSS 0.9%CVE-2022-45370MEDIUMWordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-45350LOWWordPress Simple History Plugin <= 3.3.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2023-51333HIGHPHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnEPSS 0.8%CVE-2022-44738MEDIUMWordPress Posts and Users Stats Plugin <= 1.1.3 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-41616HIGHWordPress Export Users Data CSV Plugin <= 2.1 is vulnerable to CSV InjectionEPSS 0.8%CVE-2024-24337HIGHCSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.EPSS 0.8%CVE-2023-4006HIGHImproper Neutralization of Formula Elements in a CSV File in thorsten/phpmyfaqEPSS 0.8%CVE-2024-22063HIGHZTE ZENIC ONE R58 product has a CSV injection vulnerabilityEPSS 0.8%CVE-2022-37905MEDIUMVulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequenEPSS 0.8%CVE-2022-46804MEDIUMWordPress Export Users Data Distinct Plugin <= 1.3 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-40294HIGHCSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLCEPSS 0.8%CVE-2024-55532CRITICALApache Ranger: Improper Neutralization of Formula Elements in a CSV FileEPSS 0.8%CVE-2022-46809MEDIUMWordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-42882MEDIUMWordPress Simple CSV/XLS Exporter Plugin <= 1.5.8 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-45348MEDIUMWordPress amr users Plugin <= 4.59.4 is vulnerable to CSV InjectionEPSS 0.8%CVE-2022-46821MEDIUMWordPress Emails & Newsletters with Jackmail Plugin <= 1.2.22 is vulnerable to CSV InjectionEPSS 0.8%CVE-2023-35899HIGHIBM Cloud Pak for Automation CSV injectionEPSS 0.8%CVE-2024-3214MEDIUMRelevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV InjectionEPSS 0.8%CVE-2022-38061MEDIUMWordPress Export Post Info plugin <= 1.2.0 - Authenticated CSV Injection vulnerabilityEPSS 0.7%