Vulnerabilities (CVE)

Filtered by CWE-1236
Total 252 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-9200 1 Huawei 1 Imanager Neteco 6000 2024-11-21 7.2 HIGH 7.8 HIGH
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
CVE-2020-4759 1 Ibm 1 Filenet Content Manager 2024-11-21 9.3 HIGH 7.8 HIGH
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736.
CVE-2020-36531 1 Ibm 1 Sevone Network Performance Management 2024-11-21 6.0 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely.
CVE-2020-36503 1 Connections-pro 1 Connections Business Directory 2024-11-21 6.0 MEDIUM 8.0 HIGH
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
CVE-2020-28861 1 Openasset 1 Digital Asset Management 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.
CVE-2020-28845 1 Netskope 1 Netskope 2024-11-21 9.3 HIGH 7.8 HIGH
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
CVE-2020-26507 1 Marmind 1 Marmind 2024-11-21 9.3 HIGH 7.8 HIGH
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “Notes” functionality in the main screen, an attacker can inject a payload into the “Description” field under the “Insert To-Do” option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a software such as Microsoft Excel. The attacker could gain remote access to the user’s PC.
CVE-2020-25445 1 Bookingcore 1 Booking Core 2024-11-21 6.8 MEDIUM 7.8 HIGH
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.
CVE-2020-25398 1 Mind 1 Imind Server 2024-11-21 6.8 MEDIUM 8.8 HIGH
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
CVE-2020-25170 1 Bbraun 1 Onlinesuite Application Package 2024-11-21 6.8 MEDIUM 7.8 HIGH
An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
CVE-2020-24707 1 Getgophish 1 Gophish 2024-11-21 9.3 HIGH 7.8 HIGH
Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
CVE-2020-22390 1 Akaunting 1 Akaunting 2024-11-21 6.8 MEDIUM 8.8 HIGH
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
CVE-2020-22278 1 Phpmyadmin 1 Phpmyadmin 2024-11-21 6.8 MEDIUM 8.8 HIGH
** DISPUTED ** phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents."
CVE-2020-22276 1 Weformspro 1 Weforms 2024-11-21 7.5 HIGH 9.8 CRITICAL
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
CVE-2020-22274 1 Jomsocial 1 Jomsocial 2024-11-21 7.5 HIGH 9.8 CRITICAL
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
CVE-2020-19513 1 Aida64 1 Aida64 2024-11-21 4.6 MEDIUM 7.8 HIGH
Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a crafted input that will overwrite the SEH handler.
CVE-2020-16214 1 Philips 1 Patient Information Center Ix 2024-11-21 5.8 MEDIUM 5.0 MEDIUM
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.
CVE-2020-15301 1 Salesagility 1 Suitecrm 2024-11-21 6.8 MEDIUM 7.8 HIGH
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
CVE-2020-15255 1 Anuko 1 Time Tracker 2024-11-21 6.0 MEDIUM 8.7 HIGH
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.
CVE-2020-14026 1 Ozeki 1 Ozeki Ng Sms Gateway 2024-11-21 9.3 HIGH 8.8 HIGH
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.