Vulnerabilities > CVE-2018-9106 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Acyba Acysms
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Exploit-Db
description | Joomla! Component AcySMS 3.5.0 - CSV Macro Injection. CVE-2018-9106. Webapps exploit for PHP platform |
file | exploits/php/webapps/44370.txt |
id | EDB-ID:44370 |
last seen | 2018-05-24 |
modified | 2018-03-30 |
platform | php |
port | 80 |
published | 2018-03-30 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/44370/ |
title | Joomla! Component AcySMS 3.5.0 - CSV Macro Injection |
type | webapps |
Packetstorm
data source | https://packetstormsecurity.com/files/download/146992/joomlaacysms350-inject.txt |
id | PACKETSTORM:146992 |
last seen | 2018-04-03 |
published | 2018-03-31 |
reporter | Sureshbabu Narvaneni |
source | https://packetstormsecurity.com/files/146992/Joomla-AcySMS-3.5.0-CSV-Macro-Injection.html |
title | Joomla AcySMS 3.5.0 CSV Macro Injection |