Vulnerabilities > Improper Neutralization of Formula Elements in a CSV File

DATE CVE VULNERABILITY TITLE RISK
2023-12-28 CVE-2023-50448 Improper Neutralization of Formula Elements in a CSV File vulnerability in Activeadmin
In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times.
network
low complexity
activeadmin CWE-1236
6.5
2023-12-24 CVE-2023-51763 Improper Neutralization of Formula Elements in a CSV File vulnerability in Activeadmin Active Admin
csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.
network
low complexity
activeadmin CWE-1236
critical
9.8
2023-12-07 CVE-2023-48207 Improper Neutralization of Formula Elements in a CSV File vulnerability in PHPjabbers Availability Booking Calendar 5.0
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
network
low complexity
phpjabbers CWE-1236
8.8
2023-11-17 CVE-2023-48029 Improper Neutralization of Formula Elements in a CSV File vulnerability in Corebos 5.4/5.5/7.0
Corebos 8.0 and below is vulnerable to CSV Injection.
network
low complexity
corebos CWE-1236
8.0
2023-11-07 CVE-2022-46804 Improper Neutralization of Formula Elements in a CSV File vulnerability in Narolainfotech Export Users Data Distinct 1.3
Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.
network
low complexity
narolainfotech CWE-1236
8.8
2023-11-07 CVE-2023-25983 Improper Neutralization of Formula Elements in a CSV File vulnerability in Logon KB Support
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84.
network
low complexity
logon CWE-1236
8.8
2023-09-06 CVE-2020-10131 Improper Neutralization of Formula Elements in a CSV File vulnerability in Searchblox
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
network
low complexity
searchblox CWE-1236
critical
9.8
2023-08-28 CVE-2023-22877 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Infosphere Information Server 11.7.1
IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection.
network
low complexity
ibm CWE-1236
8.8
2023-08-17 CVE-2023-38843 Improper Neutralization of Formula Elements in a CSV File vulnerability in Atlos 1.0
An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the description field in the incident function.
network
low complexity
atlos CWE-1236
8.0
2023-07-30 CVE-2023-37219 Improper Neutralization of Formula Elements in a CSV File vulnerability in Tadirantele Aeonix
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
local
low complexity
tadirantele CWE-1236
7.8