CVE-2022-2112
Improper Neutralization of Formula Elements in a CSV File in inventree/inventree
In short
A vulnerability in InvenTree allows attackers to inject malicious formulas into CSV files that execute when opened in spreadsheet applications like Excel. This can lead to arbitrary code execution on a user's computer if they open a crafted CSV export.
Technical detail
The application fails to properly sanitize formula elements (e.g., =, +, -, @) when generating CSV exports, allowing CSV injection attacks. An attacker with the ability to influence data in the system can craft payloads that execute formulas in spreadsheet clients when the CSV file is opened, potentially resulting in code execution depending on the spreadsheet application's security settings.
Summary generated and translated by AI from the official description.
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
inventree · inventree/inventreeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →