Vulnerabilities > SAP > Business ONE > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-10-12 CVE-2021-38180 Improper Neutralization of Formula Elements in a CSV File vulnerability in SAP Business ONE 10.0
SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export.
network
low complexity
sap CWE-1236
critical
9.8