Vulnerabilities > CVE-2021-40848 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Mahara

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
mahara
CWE-1236

Summary

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

Vulnerable Configurations

Part Description Count
Application
Mahara
308