CWE-1236

Improper Neutralization of Formula Elements in a CSV File

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

283 vulnerabilities with CWE-1236
CVE-2022-1202 HIGH
WP-CRM <1.2.1 - Code Injection
CVSS 7.8
CVE-2022-2027 HIGH
kromitgmbh/titra <0.77.0 - Info Disclosure
CVSS 8.0
CVE-2022-26867 MEDIUM
PowerStore SW v2.1.1.0 - Code Injection
CVSS 5.9
CVE-2022-28481 CRITICAL
CSV-Safe gem < 3.0.0 - Code Injection
CVSS 9.8
CVE-2022-1544 HIGH
Luya Yii-helpers < 1.2.1 - Command Injection
CVSS 7.8
CVE-2022-29315 HIGH
Invicti Acunetix <14 - Code Injection
CVSS 8.8
CVE-2022-0142 CRITICAL
Visual Form Builder <3.0.8 - Code Injection
CVSS 9.8
CVE-2022-23868 HIGH
RuoYi <4.7.2 - Code Injection
CVSS 7.8
CVE-2022-26249 CRITICAL
Survey King v0.3.0 - Code Injection
CVSS 9.8
CVE-2022-24770 HIGH
gradio <2.8.11 - Code Injection
CVSS 8.8
CVE-2022-22689 HIGH
CA Harvest Software Change Manager <14.0.2 - RCE
CVSS 8.8
CVE-2022-22121 HIGH
NocoDB <0.83.8 - Code Injection
CVSS 8.0
CVE-2021-47901 CRITICAL
Dirsearch 0.4.1 - Code Injection
CVSS 9.8
CVE-2021-38963 HIGH
IBM Aspera Console 3.4.0-3.4.4 - Command Injection
CVSS 8.0
CVE-2021-23286 MEDIUM
Eaton IPM Infrastructure <1.5.0plus205 - Code Injection
CVSS 5.7
CVE-2021-43257 HIGH
MantisBT <2.25.3 - Code Injection
CVSS 7.8
CVE-2021-43515 HIGH
Kimai - CSV Injection
CVSS 7.8
CVE-2021-39022 HIGH
IBM Guardium Data Encryption <5.0.0.0 - Code Injection
CVSS 8.8
CVE-2021-46363 HIGH
Magnolia <6.2.3 - Code Injection
CVSS 7.8
CVE-2021-23654 MEDIUM
html-to-csv - Code Injection
CVSS 5.6
CVE-2021-41270 MEDIUM
Symfony <4.4.35 and <5.3.12 - Code Injection
CVSS 6.5
CVE-2021-36334 MEDIUM
Dell EMC CloudLink <7.1 - Code Injection
CVSS 5.9
CVE-2021-38424 MEDIUM
Delta Electronics DIALink <1.2.4.0 - Code Injection
CVSS 5.9
CVE-2021-40848 HIGH
Mahara <21.10.0 - Code Injection
CVSS 7.8
CVE-2021-37131 MEDIUM
ManageOne - CSV Injection
CVSS 6.8
Details
Vulnerabilities 283