Vulnerabilities > CVE-2019-13144 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Mytinytodo

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mytinytodo
CWE-1236

Summary

myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.