Improper Neutralization of Formula Elements in a CSV File in inventree/inventree
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9epss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
In short
A vulnerability in InvenTree allows attackers to inject malicious formulas into CSV files that execute when opened in spreadsheet applications like Excel. This can lead to arbitrary code execution on a user's computer if they open a crafted CSV export.
Technical detail
The application fails to properly sanitize formula elements (e.g., =, +, -, @) when generating CSV exports, allowing CSV injection attacks. An attacker with the ability to influence data in the system can craft payloads that execute formulas in spreadsheet clients when the CSV file is opened, potentially resulting in code execution depending on the spreadsheet application's security settings.
Summary generated and translated by AI from the official description.
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
inventree · inventree/inventree