Falhas do tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV é gerado com dados não sanitizados, fórmulas de planilhas (Excel, LibreOffice) podem ser injetadas. Ao abrir o arquivo, a aplicação executa a fórmula automaticamente, permitindo execução arbitrária de código ou acesso a dados sensíveis do usuário.

Exemplo

Um sistema exporta um relatório CSV com dados de clientes. Um atacante injeta no banco de dados o valor '=cmd|'/c calc'!A1', que fica no CSV. Quando um analista abre em Excel, a calculadora é executada no computador dele.

Como mitigar

Prefixe células suspeitas com aspas ou espaço (='' + formula) antes de exportar, ou use formatos seguros como ODS/XLSX com validação de fórmulas. Oriente usuários a desabilitar execução automática de macros em imports.

CVE-2022-37786MEDIUMAn issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / EPSS 0.5%CVE-2023-53929MEDIUMphpMyFAQ 3.1.12 CSV Injection via User Profile ExportEPSS 0.5%CVE-2023-3493HIGHImproper Neutralization of Formula Elements in a CSV File in fossbilling/fossbillingEPSS 0.5%CVE-2020-36941MEDIUMKnockpy 4.1.1 - CSV InjectionEPSS 0.5%CVE-2021-38424MEDIUMDelta Electronics DIALinkEPSS 0.5%CVE-2022-35281MEDIUMIBM Maximo Application Suite command injectionEPSS 0.5%CVE-2023-28958HIGHIBM Watson Knowledge Catalog CSV injectionEPSS 0.5%CVE-2023-53905MEDIUMProjectSend r1605 CSV Injection via User Account Export FunctionalityEPSS 0.5%CVE-2023-5424MEDIUMWS Form LITE <= 1.9.217 - Unauthenticated CSV InjectionEPSS 0.5%CVE-2023-5527HIGHBusiness Directory Plugin <= 6.4.3 - Authenticated (Author+) CSV InjectionEPSS 0.5%CVE-2023-46401HIGHKWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.EPSS 0.5%CVE-2026-47705CRITICALTypeBot vulnerable to CSV injection in result exportEPSS 0.5%CVE-2024-3232HIGHFormula Injection VulnerabilityEPSS 0.5%CVE-2024-53260MEDIUMCourse Roster vulnerable to CSV Injection in AutolabEPSS 0.5%CVE-2026-19501HIGHCVE-2026-19501EPSS 0.5%CVE-2023-3302MEDIUMImproper Neutralization of Formula Elements in a CSV File in admidio/admidioEPSS 0.5%CVE-2026-86745MEDIUMSnipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping ExportEPSS 0.4%CVE-2023-45597MEDIUMA CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web apEPSS 0.4%CVE-2024-25007HIGHEricsson Network Manager - Improper Neutralization of Formula Elements VulnerabilityEPSS 0.4%CVE-2024-51094HIGHAn issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into EPSS 0.4%