Vulnerabilities > Improper Neutralization of Formula Elements in a CSV File

DATE CVE VULNERABILITY TITLE RISK
2021-03-18 CVE-2021-24144 Improper Neutralization of Formula Elements in a CSV File vulnerability in Ciphercoin Contact Form 7 Database Addon
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
local
low complexity
ciphercoin CWE-1236
7.8
2021-03-03 CVE-2021-27839 Improper Neutralization of Formula Elements in a CSV File vulnerability in Bigprof Online Invoicing System
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.
network
bigprof CWE-1236
5.8
2021-02-26 CVE-2021-21302 Improper Neutralization of Formula Elements in a CSV File vulnerability in Prestashop
PrestaShop is a fully scalable open source e-commerce solution.
network
low complexity
prestashop CWE-1236
6.5
2021-02-19 CVE-2020-19513 Improper Neutralization of Formula Elements in a CSV File vulnerability in Aida64 6.00.5100
Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a crafted input that will overwrite the SEH handler.
local
low complexity
aida64 CWE-1236
4.6
2021-02-06 CVE-2020-9205 Improper Neutralization of Formula Elements in a CSV File vulnerability in Huawei Manageone 8.0.1
There has a CSV injection vulnerability in ManageOne 8.0.1.
network
low complexity
huawei CWE-1236
4.0
2021-01-26 CVE-2021-3188 Improper Neutralization of Formula Elements in a CSV File vulnerability in PHPlist 3.6.0
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
network
low complexity
phplist CWE-1236
critical
10.0
2020-12-24 CVE-2020-9200 Improper Neutralization of Formula Elements in a CSV File vulnerability in Huawei Imanager Neteco 6000 V600R021C00
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00.
local
low complexity
huawei CWE-1236
7.2
2020-12-14 CVE-2020-28861 Improper Neutralization of Formula Elements in a CSV File vulnerability in Openasset Digital Asset Management
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.
network
low complexity
openasset CWE-1236
5.0
2020-11-20 CVE-2020-28845 Improper Neutralization of Formula Elements in a CSV File vulnerability in Netskope 75.0
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
network
netskope CWE-1236
critical
9.3
2020-11-18 CVE-2020-15301 Improper Neutralization of Formula Elements in a CSV File vulnerability in Salesagility Suitecrm
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules.
6.8