CVE-2021-41824Improper Neutralization of Formula Elements in a CSV File in CMS

Severity
HIGH
No vector
EPSS
0.5%
top 33.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 18

Description

CSV Injection Vulnerability ### Impact In some circumstances, it was possible to export data in CSV format that could trigger a payload in old versions of Excel. If you are accepting user input from untrusted sources and will be exporting that data in CSV format from element index pages and there is a chance users will open that on old versions of Excel, then you should update. ### Patches This has been patched in Craft 3.7.14. ### References * https://github.com/craftcms/cms/blob/develop/CH

Affected Packages1 packages

Packagistcraftcms/cms3.4.03.7.14

🔴Vulnerability Details

2
OSV
CSV Injection Vulnerability2021-10-18
GHSA
CSV Injection Vulnerability2021-10-18
CVE-2021-41824 — Craftcms CMS vulnerability | cvebase