Product Referenceproduct
https://codecanyon.net/item/erpgo-saas-all-in-one-business-erp-with-project-account-hrm-crm-pos/33263426 CVE-2023-54348
HIGH
ERPGo SaaS 3.9 CSV Injection via Vendor Creation
Record summary
CVE-2023-54348 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas into vendor name fields that execute on the workstation of users who open the exported CSV in a spreadsheet application. Attackers can add malicious formulas like =10+20+cmd|' /C calc'!A0 in the vendor creation form, which execute when the exported CSV file is opened in spreadsheet applications.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ERPGo SaaSBrowse Rajodiya / ERPGo SaaS | CVE List | 3.9 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBERPGo SaaS 3.9 - CSV InjectionExploitDB exploitby Sajibe KantiNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-54348 Official Product Homepageproduct
https://rajodiya.com/ ExploitDB-51220exploit
https://www.exploit-db.com/exploits/51220 VulnCheck Advisory: ERPGo SaaS 3.9 CSV Injection via Vendor CreationThird-party advisory
https://www.vulncheck.com/advisories/erpgo-saas-csv-injection-via-vendor-creation