Falhas do tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV é gerado com dados não sanitizados, fórmulas de planilhas (Excel, LibreOffice) podem ser injetadas. Ao abrir o arquivo, a aplicação executa a fórmula automaticamente, permitindo execução arbitrária de código ou acesso a dados sensíveis do usuário.

Exemplo

Um sistema exporta um relatório CSV com dados de clientes. Um atacante injeta no banco de dados o valor '=cmd|'/c calc'!A1', que fica no CSV. Quando um analista abre em Excel, a calculadora é executada no computador dele.

Como mitigar

Prefixe células suspeitas com aspas ou espaço (='' + formula) antes de exportar, ou use formatos seguros como ODS/XLSX com validação de fórmulas. Oriente usuários a desabilitar execução automática de macros em imports.

CVE-2023-25348HIGHChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new peEPSS 0.4%CVE-2024-27785MEDIUMAn improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenEPSS 0.4%CVE-2026-14846MEDIUMIncorrect neutralisation in the PrestaShop firmwareEPSS 0.4%CVE-2021-23286MEDIUMSecurity issues in Eaton Intelligent Power Manager InfrastructureEPSS 0.4%CVE-2024-45084HIGHIBM Cognos Controller CSV injectionEPSS 0.4%CVE-2024-9102MEDIUMphpLDAPadmin: Improper Neutralization of Formula ElementsEPSS 0.4%CVE-2025-60852MEDIUMA CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versionsEPSS 0.4%CVE-2023-51298MEDIUMPHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulEPSS 0.4%CVE-2023-2629MEDIUMImproper Neutralization of Formula Elements in a CSV File in pimcore/customer-data-frameworkEPSS 0.4%CVE-2021-47901MEDIUMdirsearch 0.4.1 - CSV InjectionEPSS 0.4%CVE-2025-50572HIGHArcher 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be execEPSS 0.4%CVE-2025-62417HIGHbagisto - CSV Formula Injection in Create New ProductEPSS 0.4%CVE-2026-18738MEDIUMShlink CSV Formula Injection via Visit Export CLIEPSS 0.4%CVE-2026-47693MEDIUMPoweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applicationsEPSS 0.4%CVE-2023-46400MEDIUMKWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.EPSS 0.4%CVE-2026-39424MEDIUMMaxKB has CSV Injection in its Application Chat Export FunctionalityEPSS 0.4%CVE-2023-54348HIGHERPGo SaaS 3.9 CSV Injection via Vendor CreationEPSS 0.4%CVE-2025-14229MEDIUMSourceCodester Inventory Management System SVC Report Export csv injectionEPSS 0.4%CVE-2025-39245MEDIUMThere is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands vEPSS 0.3%CVE-2025-11254MEDIUMContest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV InjectionEPSS 0.3%