Fallos del tipo CWE-1236

178 resultados

Falta de neutralização de fórmulas em arquivos CSV

Quando um arquivo CSV contém fórmulas (como =cmd|'/c calc'!A1 ou =1+1), aplicativos que abrem o arquivo automaticamente as interpretam e executam, permitindo injeção de código. O risco é alto porque o usuário apenas abre um arquivo aparentemente inofensivo e o aplicativo (Excel, Calc, etc.) executa comandos maliciosos sem aviso adequado.

Ejemplo

Um relatório exportado em CSV com dados de usuários contém um campo começando com '=' que, quando aberto no Excel, executa uma macro ou comando do sistema. Um atacante injeta a fórmula no banco de dados ou upload de arquivo, e qualquer pessoa que baixe e abra o CSV sofre o ataque.

Cómo mitigar

Prefixe campos suspeitos com um caractere neutro (como aspas simples ou espaço) antes de gerar o CSV, ou configure o aplicativo para não interpretar fórmulas automaticamente. Na aplicação, valide e escape qualquer conteúdo que inicie com caracteres de fórmula (=, +, -, @, tabulação).

CVE-2020-36962MEDIUMTendenci 12.3.1 - CSV/ Formula InjectionEPSS 10.7%CVE-2022-0142Visual Form Builder < 3.0.6 - CSV InjectionEPSS 2.7%CVE-2022-1544HIGHFormula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in luyadev/yii-helpersEPSS 2.4%CVE-2019-17661HIGHA CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control EPSS 2.4%CVE-2023-29918MEDIUMRosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.EPSS 2.2%CVE-2021-38180SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitatiEPSS 2.1%CVE-2024-29375CRITICALCSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to tEPSS 1.5%CVE-2022-1539Exports and Reports < 0.9.2 - Contributor+ CSV InjectionEPSS 1.5%CVE-2022-2240Request a Quote <= 2.3.7 - CSV InjectionEPSS 1.4%CVE-2021-41270MEDIUMCSV Injection in SymfonyEPSS 1.4%CVE-2022-3574CRITICALWPForms Pro < 1.7.7 - CSV InjectionEPSS 1.3%CVE-2021-24441Sign-up Sheets < 1.0.14 - Authenticated CSV InjectionEPSS 1.3%CVE-2022-24770HIGHImproper Neutralization of Formula Elements in a CSV File in Gradio FlaggingEPSS 1.3%CVE-2022-3393CRITICALPost to CSV by BestWebSoft <= 1.4.0 - Author+ CSV InjectionEPSS 1.3%CVE-2022-22689CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, dueEPSS 1.3%CVE-2022-3463CRITICALFluentForm < 4.3.13 - CSV InjectionEPSS 1.2%CVE-2022-22121HIGHNocoDB - CSV Injection in User ManagementEPSS 1.2%CVE-2022-2112CRITICALImproper Neutralization of Formula Elements in a CSV File in inventree/inventreeEPSS 1.2%CVE-2020-36503Connections Business Directory < 9.7 - Admin+ CSV InjectionEPSS 1.2%CVE-2021-25960HIGHSuiteCRM - CSV Injection in Accounts ModuleEPSS 1.2%