Vulnerabilities > CVE-2018-7201 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Projectsend

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
projectsend
CWE-1236

Summary

CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.