Falhas do tipo CWE-1236

190 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV é gerado com dados não sanitizados, fórmulas de planilhas (Excel, LibreOffice) podem ser injetadas. Ao abrir o arquivo, a aplicação executa a fórmula automaticamente, permitindo execução arbitrária de código ou acesso a dados sensíveis do usuário.

Exemplo

Um sistema exporta um relatório CSV com dados de clientes. Um atacante injeta no banco de dados o valor '=cmd|'/c calc'!A1', que fica no CSV. Quando um analista abre em Excel, a calculadora é executada no computador dele.

Como mitigar

Prefixe células suspeitas com aspas ou espaço (='' + formula) antes de exportar, ou use formatos seguros como ODS/XLSX com validação de fórmulas. Oriente usuários a desabilitar execução automática de macros em imports.

CVE-2025-67851MEDIUMMoodle: moodle: formula injection allows arbitrary formula execution via unescaped data exportEPSS 0.3%CVE-2023-25611MEDIUMA improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 EPSS 0.3%CVE-2026-76797MEDIUMMongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated ReportsEPSS 0.3%CVE-2026-10248MEDIUMSourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supplier csv injectionEPSS 0.2%CVE-2024-28764MEDIUMIBM WebSphere Automation CSV injectionEPSS 0.2%CVE-2025-54752MEDIUMMultiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victiEPSS 0.2%CVE-2025-52386MEDIUMCycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON fileEPSS 0.2%CVE-2025-1421LOWFormula injection in a CSV file in Proget MDMEPSS 0.2%CVE-2025-35033MEDIUMMedical Informatics Engineering Enterprise Health CSV injectionEPSS 0.2%CVE-2025-58855HIGHWordPress AP HoneyPot WordPress Plugin Plugin <= 1.4 - Cross Site Request Forgery (CSRF) VulnerabilityEPSS 0.2%CVE-2026-55452MEDIUMSnipe-IT: CSV formula injection in Activity Report exportEPSS 0.2%CVE-2026-24447MEDIUMIf a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When EPSS 0.2%CVE-2026-27644MEDIUMtraccar allows CSV formula injection via exported position dataEPSS 0.2%CVE-2025-6838MEDIUMBroken Link Notifier <= 1.3.0 - Authenticated (Contributor+) CSV InjectionEPSS 0.2%CVE-2023-37219HIGH Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV FileEPSS 0.2%CVE-2025-11279MEDIUMAxosoft Scrum and Bug Tracking Add Work Item csv injectionEPSS 0.2%CVE-2025-61873LOWBest Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.EPSS 0.2%CVE-2026-64955MEDIUMVelociraptor CSV Formula Injection in Export PipelineEPSS 0.2%CVE-2026-42267MEDIUMKimai: Formula Injection via tag names in XLSX exportEPSS 0.2%CVE-2026-79971MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper SanitizaEPSS 0.2%