Vulnerabilities > CVE-2018-9106 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Acyba Acysms

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
acyba
CWE-1236
exploit available

Summary

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.

Exploit-Db

descriptionJoomla! Component AcySMS 3.5.0 - CSV Macro Injection. CVE-2018-9106. Webapps exploit for PHP platform
fileexploits/php/webapps/44370.txt
idEDB-ID:44370
last seen2018-05-24
modified2018-03-30
platformphp
port80
published2018-03-30
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44370/
titleJoomla! Component AcySMS 3.5.0 - CSV Macro Injection
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/146992/joomlaacysms350-inject.txt
idPACKETSTORM:146992
last seen2018-04-03
published2018-03-31
reporterSureshbabu Narvaneni
sourcehttps://packetstormsecurity.com/files/146992/Joomla-AcySMS-3.5.0-CSV-Macro-Injection.html
titleJoomla AcySMS 3.5.0 CSV Macro Injection