Description

In the CSV export feature of the CMS it's possible for the output to contain macros and scripts, which if imported without sanitisation into software (including Microsoft Excel) may be executed. In order to safeguard against this threat all potentially executable cell values exported from CSV will be prepended with a literal tab character.

Description source: GitHub Advisory

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory3.5.0-rc1 to < 3.5.6 · Fixed in 3.5.6affected
3.6.0-rc1 to < 3.6.3 · Fixed in 3.6.3affected
4.0.0-rc1 to < 4.0.1 · Fixed in 4.0.1affected

References

6