CVE-2017-18049

MEDIUM

SilverStripe < 3.5.6, 3.6.x < 3.6.3, 4.x < 4.0.1 - CSV Injection via User Profile Fields

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-18049. PoCs published by Ishaq Mohammed.

AI-analyzed exploit summary This exploit demonstrates a CSV Excel Macro Injection vulnerability in SilverStripe CMS 3.6.2. By injecting a malicious payload into a user profile field, an attacker can generate a CSV file that, when opened in a spreadsheet application like Microsoft Excel, may execute arbitrary commands.

Description

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ishaq Mohammed · textwebappsphp
https://www.exploit-db.com/exploits/43396

This exploit demonstrates a CSV Excel Macro Injection vulnerability in SilverStripe CMS 3.6.2. By injecting a malicious payload into a user profile field, an attacker can generate a CSV file that, when opened in a spreadsheet application like Microsoft Excel, may execute arbitrary commands.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: SilverStripe CMS 3.6.2
Auth required
Prerequisites: Valid user credentials · Access to the admin profile page · Ability to export CSV files
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43396/

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 44.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-74
Status published
Products (3)
silverstripe/framework 0 - 3.5.6Packagist
silverstripe/silverstripe 4.0.0
silverstripe/silverstripe < 3.5.5
Published Jan 23, 2018
Tracked Since Feb 18, 2026