CVE-2020-25445

The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bookingcore:booking_core:1.7.0:*:*:*:*:*:*:*

History

16 Jul 2021, 20:23

Type Values Removed Values Added
CWE CWE-1236
CPE cpe:2.3:a:bookingcore:booking_core:1.7.0:*:*:*:*:*:*:*
References (MISC) https://medium.com/@singh.satyam158/vulnerabilities-in-booking-core-1-7-d85d1dfae44e - (MISC) https://medium.com/@singh.satyam158/vulnerabilities-in-booking-core-1-7-d85d1dfae44e - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8

14 Jul 2021, 20:15

Type Values Removed Values Added
Summary Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0. The “Subscribe” feature of the application is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result, when an admin in the backend downloads and opens the CSV, the content of the cells is executed. Vulnerable fields: First name and Last name of the “Subscribe” request. The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.

14 Jul 2021, 15:52

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-14 15:15

Updated : 2024-02-04 21:47


NVD link : CVE-2020-25445

Mitre link : CVE-2020-25445

CVE.ORG link : CVE-2020-25445


JSON object : View

Products Affected

bookingcore

  • booking_core
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File