Vulnerabilities > Improper Neutralization of Formula Elements in a CSV File

DATE CVE VULNERABILITY TITLE RISK
2020-12-14 CVE-2020-28861 Improper Neutralization of Formula Elements in a CSV File vulnerability in Openasset Digital Asset Management
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.
network
low complexity
openasset CWE-1236
5.3
2020-12-11 CVE-2020-4633 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Resilient Security Orchestration Automation and Response 38.0
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
network
low complexity
ibm CWE-1236
8.8
2020-11-30 CVE-2020-4627 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Cloud PAK for Security 1.3.0.1
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection.
network
low complexity
ibm CWE-1236
critical
9.0
2020-11-20 CVE-2020-28845 Improper Neutralization of Formula Elements in a CSV File vulnerability in Netskope 75.0
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
local
low complexity
netskope CWE-1236
7.8
2020-11-18 CVE-2020-15301 Improper Neutralization of Formula Elements in a CSV File vulnerability in Salesagility Suitecrm
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules.
local
low complexity
salesagility CWE-1236
7.8
2020-11-09 CVE-2020-4759 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Filenet Content Manager 5.5.4/5.5.5
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection.
local
low complexity
ibm CWE-1236
7.8
2020-11-05 CVE-2020-26507 Improper Neutralization of Formula Elements in a CSV File vulnerability in Marmind 4.1.141.0
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers.
local
low complexity
marmind CWE-1236
7.8
2020-11-05 CVE-2020-25398 Improper Neutralization of Formula Elements in a CSV File vulnerability in Mind Imind Server 3.13.65
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
network
low complexity
mind CWE-1236
8.8
2020-11-04 CVE-2020-22274 Improper Neutralization of Formula Elements in a CSV File vulnerability in Jomsocial 4.7.6
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
network
low complexity
jomsocial CWE-1236
critical
9.8
2020-11-04 CVE-2020-22278 Improper Neutralization of Formula Elements in a CSV File vulnerability in PHPmyadmin
phpMyAdmin through 5.0.2 allows CSV injection via Export Section.
network
low complexity
phpmyadmin CWE-1236
8.8