Vulnerabilities > CVE-2021-43257 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Mantisbt

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
mantisbt
CWE-1236

Summary

Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.

Vulnerable Configurations

Part Description Count
Application
Mantisbt
176