CWE-1236
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
292 vulnerabilities with CWE-1236
CVE-2020-24707
HIGH
gophish < 0.11.0 - CSV Injection
CVSS 7.8
CVE-2020-15255
HIGH
Anuko Time Tracker <1.19.23.5325 - Info Disclosure
CVSS 8.7
CVE-2020-4689
MEDIUM
IBM Security Guardium 11.2 - Command Injection
CVSS 6.8
CVE-2020-4302
HIGH
IBM Cognos Analytics 11.0-11.1 - Remote Code Execution via CSV Injection
CVSS 7.8
CVE-2020-14026
HIGH
Ozeki NG SMS Gateway <4.17.6 - Code Injection
CVSS 8.8
CVE-2020-16214
MEDIUM
Philips Patient Information Center iX B.02 C.02 C.03 - CSV Injection
CVSS 5.0
CVE-2020-13826
HIGH
i-doit < 1.14.2 - CSV Injection via Title Parameter
CVSS 8.8
CVE-2020-10780
MEDIUM
Red Hat CloudForms 4.7-5 - CSV Injection
CVSS 6.3
CVE-2020-7049
HIGH
Nozomi Networks OS <19.0.4 - CSV Injection
CVSS 7.3
CVE-2020-13247
HIGH
BooleBox Secure File Sharing Utility <4.2.3.0 - Code Injection
CVSS 7.3
CVE-2020-13146
HIGH
Open edX Ironwood 2.5 - Code Injection
CVSS 8.8
CVE-2020-11548
CRITICAL
Search Meter < 2.13.2 - Remote Code Execution via CSV Injection in Search Export
CVSS 9.8
CVE-2020-7947
CRITICAL
WordPress Login by Auth0 <4.0.0 - CSV Injection
CVSS 9.8
CVE-2020-9347
CRITICAL
Zoho ManageEngine Password Manager Pro <10.x - Code Injection
CVSS 9.8
CVE-2020-10460
MEDIUM
Chadha PHPKB Standard Multi-Language 9 - Code Injection
CVSS 4.9
CVE-2020-9372
HIGH
Appointment Booking Calendar < 1.3.35 - CSV Injection via Booking Form Fields
CVSS 7.8
CVE-2020-9466
MEDIUM
Export Users to CSV < 1.4.2 - CSV Injection
CVSS 6.1
CVE-2020-9017
HIGH
LiteCart < 2.2.1 - CSV Injection via Customer Profile
CVSS 8.0
CVE-2019-16959
MEDIUM
SolarWinds Web Help Desk 12.7.0 - Code Injection
CVSS 6.5
CVE-2019-20002
HIGH
SolarWinds WebHelpDesk 12.7.1 - Code Injection
CVSS 7.8
CVE-2019-19676
CRITICAL
arxes-tolina 3.0.0 - CSV Injection via Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung Columns
CVSS 9.6
CVE-2019-20184
HIGH
KeePass 2.4.1 - CSV Injection via Title Field in CSV Export
CVSS 7.8
CVE-2019-20180
MEDIUM
TablePress < 1.9.2 - CSV Injection via tablepress[data]
CVSS 6.8
CVE-2019-13181
MEDIUM
SolarWinds Serv-U FTP Server <15.1.7 - SQL Injection
CVSS 6.5
CVE-2019-0403
CRITICAL
SAP Enable Now < 1911 - CSV Command Injection
CVSS 9.8
Details
Vulnerabilities
292