Falhas do tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV é gerado com dados não sanitizados, fórmulas de planilhas (Excel, LibreOffice) podem ser injetadas. Ao abrir o arquivo, a aplicação executa a fórmula automaticamente, permitindo execução arbitrária de código ou acesso a dados sensíveis do usuário.

Exemplo

Um sistema exporta um relatório CSV com dados de clientes. Um atacante injeta no banco de dados o valor '=cmd|'/c calc'!A1', que fica no CSV. Quando um analista abre em Excel, a calculadora é executada no computador dele.

Como mitigar

Prefixe células suspeitas com aspas ou espaço (='' + formula) antes de exportar, ou use formatos seguros como ODS/XLSX com validação de fórmulas. Oriente usuários a desabilitar execução automática de macros em imports.

CVE-2024-28111MEDIUMCSV Injection in exported history CSV filesEPSS 0.6%CVE-2025-55745LOWUnoPim Quick Export feature is vulnerable to CSV injectionEPSS 0.6%CVE-2022-45810MEDIUMWordPress Email Subscribers & Newsletters Plugin <= 5.5.2 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-22719MEDIUMWordPress GiveWP Plugin <= 2.25.1 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-51302HIGHPHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulneEPSS 0.6%CVE-2022-45360MEDIUMWordPress Commenter Emails Plugin <= 2.6.1 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-23678MEDIUMWordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin <= 2.2.5 is vulnerable to CSV InjectionEPSS 0.6%CVE-2022-38702MEDIUMWordPress WP CSV Exporter Plugin <= 2.0 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-23796MEDIUMWordPress Form Builder Plugin <= 1.9.9.0 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-41798MEDIUMWordPress Directorist Plugin <= 7.7.1 is vulnerable to CSV InjectionEPSS 0.6%CVE-2023-36527MEDIUMWordPress Post to CSV by BestWebSoft Plugin <= 1.4.0 is vulnerable to CSV InjectionEPSS 0.6%CVE-2020-16214Philips Patient Monitoring Devices Improper Neutralization of Formula Elements in a CSV FileEPSS 0.6%CVE-2022-26867MEDIUMPowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation oEPSS 0.6%CVE-2022-44830HIGHSourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and EPSS 0.6%CVE-2024-47572HIGHAn improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorizEPSS 0.6%CVE-2026-23873MEDIUMHUSTOJ is Vulnerable to Stored CSV Injection (Formula Injection) in Contest Rank ExportEPSS 0.6%CVE-2023-3527MEDIUMAvaya Call Management System CSV injection vulnerabilityEPSS 0.6%CVE-2024-41226HIGHA CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted pEPSS 0.6%CVE-2023-47295CRITICALA CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload EPSS 0.6%CVE-2024-47485MEDIUMThere is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to geneEPSS 0.6%