CWE-1236

Improper Neutralization of Formula Elements in a CSV File

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

283 vulnerabilities with CWE-1236
CVE-2024-25007 HIGH
Ericsson Network Manager <23.1 - XSS
CVSS 7.1
CVE-2024-29375 CRITICAL
Addactis IBNRS <3.10.3.107 - Code Injection
CVSS 9.8
CVE-2024-28111 MEDIUM
Canarytokens - CSV Injection
CVSS 6.5
CVE-2024-24337 HIGH
Koha Library Management System <23.05.05 - CSV Injection
CVSS 8.0
CVE-2023-53929 HIGH
phpMyFAQ 3.1.12 - Code Injection
CVSS 8.8
CVE-2023-53913 HIGH
Rukovoditel 3.3.1 - Code Injection
CVSS 8.8
CVE-2023-53905 HIGH
ProjectSend r1605 - Code Injection
CVSS 8.0
CVE-2023-47295 CRITICAL
NCR Terminal Handler 1.5.1 - Command Injection
CVSS 9.8
CVE-2023-51336 HIGH
PHPJabbers Meeting Room Booking System v1.0 - Code Injection
CVSS 8.8
CVE-2023-51333 HIGH
PHPJabbers Cinema Booking System v1.0 - Code Injection
CVSS 8.8
CVE-2023-51319 HIGH
PHPJabbers Bus Reservation System v1.1 - Code Injection
CVSS 8.8
CVE-2023-51311 HIGH
PHPJabbers Car Park Booking System v3.0 - Code Injection
CVSS 8.8
CVE-2023-51302 HIGH
PHPJabbers Hotel Booking System <4.0 - Code Injection
CVSS 8.8
CVE-2023-51298 MEDIUM
PHPJabbers Event Booking Calendar v4.0 - Code Injection
CVSS 4.7
CVE-2023-46401 CRITICAL
KWHotel 0.47 - Code Injection
CVSS 9.8
CVE-2023-46400 CRITICAL
KWHotel 0.47 - Code Injection
CVSS 9.8
CVE-2023-5527 HIGH
Business Directory Plugin <6.4.3 - Code Injection
CVSS 7.4
CVE-2023-5424 MEDIUM
WS Form LITE <1.9.217 - Code Injection
CVSS 4.7
CVE-2023-48709 HIGH
iTop - RCE
CVSS 8.0
CVE-2023-35899 HIGH
IBM Cloud Pak for Automation <22.0.2 - Code Injection
CVSS 7.0
CVE-2023-47534 CRITICAL
Fortinet FortiClientEMS <7.2.2-6.0.8 - Code Injection
CVSS 9.6
CVE-2023-45597 MEDIUM
AiLux imx6 <imx6_1.0.7-2 - Info Disclosure
CVSS 5.9
CVE-2023-47022 MEDIUM
NCR Terminal Handler <1.5.1 - Info Disclosure
CVSS 6.5
CVE-2023-31295 HIGH
Sesami CPTO <6.3.8.6 - Info Disclosure
CVSS 7.5
CVE-2023-31296 MEDIUM
Sesami CPTO <6.3.8.6 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 283