github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-007-1.yaml GHSA-MQJC-X563-C9Q8
silverstripe/framework CSV Excel Macro Injection
Description
In the CSV export feature of the CMS it's possible for the output to contain macros and scripts, which if imported without sanitisation into software (including Microsoft Excel) may be executed. In order to safeguard against this threat all potentially executable cell values exported from CSV will be prepended with a literal tab character.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
silverstripe/frameworkBrowse Packagist / silverstripe/framework | GitHub Advisory | 3.5.0-rc1 to < 3.5.6 · Fixed in 3.5.6 | affected |
| 3.6.0-rc1 to < 3.6.3 · Fixed in 3.6.3 | affected | ||
| 4.0.0-rc1 to < 4.0.1 · Fixed in 4.0.1 | affected |
References
6github.com
https://github.com/silverstripe/silverstripe-framework github.com
https://github.com/silverstripe/silverstripe-framework/commit/55739fa5af6171594b2cb4f3621d5fcce5e887d4 github.com
https://github.com/silverstripe/silverstripe-framework/commit/cfe1d4f481bf53ea8da2b8608a563e207d923df9 github.com
https://github.com/silverstripe/silverstripe-framework/commit/dd4c5417e7592e29e698af428b72bdb9b6729797 silverstripe.org
https://www.silverstripe.org/download/security-releases/ss-2017-007