CVE-2023-1236
published 2023-03-07CVE-2023-1236: Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML…
PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.46%
37.5th percentile
Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activeadmin | activeadmin | >= 0 < 2.12.0 | 2.12.0 |
| admidio | admidio | >= 0 < 4.2.9 | 4.2.9 |
| chromium | chromium | >= 0 < 111.0.5563.64-1~deb11u1 | 111.0.5563.64-1~deb11u1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| debian | chromium | < chromium 111.0.5563.64-1 (bookworm) | chromium 111.0.5563.64-1 (bookworm) |
| fortinet | fortianalyzer | — | — |
| fortinet | forticlientems | — | — |
| fortinet | forticlientendpointmanagementserver | — | — |
| fortinet | fortinet | — | — |
| francoisjacquet | rosariosis | 0 – 10.8.4 | — |
| chrome | < 111.0.5563.64 | 111.0.5563.64 | |
| chrome | >= 111.0.5563.64 < 111.0.5563.64 | 111.0.5563.64 | |
| chrome_chrome | — | — | |
| linux | linux_kernel | >= 6.2.0 < 6.4.8 | 6.4.8 |
| msrc | microsoft_edge | — | — |
| phpmyfaq | phpmyfaq | 0 – 3.1.12 | — |
| pimcore | customer-management-framework-bundle | >= 0 < 3.3.9 | 3.3.9 |
| thorsten | phpmyfaq | >= 0 < 3.1.16 | 3.1.16 |
| thorsten | phpmyfaq | 0 – 3.1.12 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_redhat5.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0...
vendor_fortinet·2024-03-12·CVSS 9.6
CVE-2023-47534 [CRITICAL] CWE-1236 A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0...
FG-IR-23-390: A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0...
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVEs: CVE-2023-47534
CWEs: CWE-1236
CVSS: 9.6 (critical)
Affected products: FortiClientEMS, FortiClientendpointmanagementserver, Fortinet
Microsoft
Chromium: CVE-2023-1236 Inappropriate implementation in Internals
vendor_msrc·2023-03-14·CVSS 4.3
CVE-2023-1236 [MEDIUM] Chromium: CVE-2023-1236 Inappropriate implementation in Internals
Chromium: CVE-2023-1236 Inappropriate implementation in Internals
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft
Ubuntu
Chromium vulnerabilities
vendor_ubuntu·2023-03-13·CVSS 8.8
CVE-2023-1213 [HIGH] Chromium vulnerabilities
Title: Chromium vulnerabilities
Summary: Several security issues were fixed in Chromium.
It was discovered that Chromium could be made to write out of bounds in
several components. A remote attacker could possibly use this issue to
corrupt memory via a crafted HTML page, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2023-0930, CVE-2023-1219,
CVE-2023-1220, CVE-2023-1222)
It was discovered that Chromium contained an integer overflow in the PDF
component. A remote attacker could possibly use this issue to corrupt
memory via a crafted PDF file, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2023-0933)
It was discovered that Chromium did not properly manage memory in several
components. A remote attacker could possibly use this issue
Chrome
Stable Channel Update for Desktop: CVE-2023-1236
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1236 [LOW] Stable Channel Update for Desktop: CVE-2023-1236
Stable Channel Update for Desktop
CVE-2023-1236: Inappropriate implementation in Internals. Reported by Alesandro Ortiz on 2022-10-14 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: low
Fortinet
CSV injection in macro name
vendor_fortinet·2023-03-07·CVSS 4.0
CVE-2023-25611 [MEDIUM] CWE-1236 CSV injection in macro name
FG-IR-22-488: CSV injection in macro name
A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inserting spreadsheet formulas in macro names.
CVEs: CVE-2023-25611
CWEs: CWE-1236
CVSS: 4.0 (medium)
Affected products: FortiAnalyzer, Fortinet
Debian
CVE-2023-1236: chromium - Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.6...
vendor_debian·2023·CVSS 4.3
CVE-2023-1236 [MEDIUM] CVE-2023-1236: chromium - Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.6...
Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
sid: resolved (fixed in 111.0.5563.64-1)
trixie: resolved (fixed in 111.0.5563.64-1)
OSV
iommufd: Set end correctly when doing batch carry
osv·2025-12-24
CVE-2023-54060 iommufd: Set end correctly when doing batch carry
iommufd: Set end correctly when doing batch carry
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Set end correctly when doing batch carry
Even though the test suite covers this it somehow became obscured that
this wasn't working.
The test iommufd_ioas.mock_domain.access_domain_destory would blow up
rarely.
end should be set to 1 because this just pushed an item, the carry, to the
pfns list.
Sometimes the test would blow up with:
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: 0000 [#1] SMP
CPU: 5 PID: 584 Comm: iommufd Not tainted 6.5.0-rc1-dirty #1236
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-
GHSA
phpMyFAQ contains a CSV injection vulnerability
ghsa·2025-12-18
CVE-2023-53929 [MEDIUM] CWE-1236 phpMyFAQ contains a CSV injection vulnerability
phpMyFAQ contains a CSV injection vulnerability
phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attackers can modify their user profile name with a payload like 'calc|a!z|' to trigger code execution when an administrator exports user data as a CSV file.
GHSA
ActiveAdmin CSV Injection leading to sensitive information disclosure
ghsa·2023-12-28
CVE-2023-51763 [MEDIUM] CWE-1236 ActiveAdmin CSV Injection leading to sensitive information disclosure
ActiveAdmin CSV Injection leading to sensitive information disclosure
### Impact
In ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration.
The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program.
### Patches
Versions 3.2.0 and above fixed the problem by escaping any data starting with `=` and other characters used by spreadsheet programs.
### Workarounds
Only turn on formula evaluation in spreadsheet programs when importing CS
GHSA
Potential CSV export data leak
ghsa·2023-12-15
CVE-2023-50448 [HIGH] CWE-1236 Potential CSV export data leak
Potential CSV export data leak
### Impact
In ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user.
The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized.
The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request.
### Patches
Versions 2.12.0 and above fixed the problem by completely removing the s
GHSA
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File vulnerability
ghsa·2023-07-31
CVE-2023-4006 [HIGH] CWE-1236 phpMyFAQ Improper Neutralization of Formula Elements in a CSV File vulnerability
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File vulnerability
Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
GHSA
Admidio Improper Neutralization of Formula Elements in a CSV File vulnerability
ghsa·2023-06-23
CVE-2023-3302 [HIGH] CWE-1236 Admidio Improper Neutralization of Formula Elements in a CSV File vulnerability
Admidio Improper Neutralization of Formula Elements in a CSV File vulnerability
Admidio prior to 4.2.9 is vulnerable toImproper Neutralization of Formula Elements in a CSV File.
GHSA
Embedding untrusted input inside CSV files leads to Formula Injection/CSV Injection
ghsa·2023-05-11
CVE-2023-2629 [HIGH] CWE-1236 Embedding untrusted input inside CSV files leads to Formula Injection/CSV Injection
Embedding untrusted input inside CSV files leads to Formula Injection/CSV Injection
### Impact
The pimcore application is vulnerable to Formula Injection/CSV Injection via the Firstname, Lastname, Street, Zip & City input fields. These vulnerabilities allow unauthenticated attackers to execute arbitrary code via a crafted excel file.
Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.
### Patches
Update to version 3.3.9 or apply this patch manually https://github.com/pimcore/customer-data-framework/commit/4e0105c3a78d20686a0c010faef27d2297b98803.patch
### Workarounds
Apply patch https://github.com/pimcore/customer-data-framework/commit/4e0105c3a78d20686a0c010faef27d2297b98803.patch m
GHSA
RosarioSIS vulnerable to CSV Injection
ghsa·2023-05-02
CVE-2023-29918 [MEDIUM] CWE-1236 RosarioSIS vulnerable to CSV Injection
RosarioSIS vulnerable to CSV Injection
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
OSV
chromium-browser vulnerabilities
osv·2023-03-13·CVSS 8.8
CVE-2023-0930 [HIGH] chromium-browser vulnerabilities
chromium-browser vulnerabilities
It was discovered that Chromium could be made to write out of bounds in
several components. A remote attacker could possibly use this issue to
corrupt memory via a crafted HTML page, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2023-0930, CVE-2023-1219,
CVE-2023-1220, CVE-2023-1222)
It was discovered that Chromium contained an integer overflow in the PDF
component. A remote attacker could possibly use this issue to corrupt
memory via a crafted PDF file, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2023-0933)
It was discovered that Chromium did not properly manage memory in several
components. A remote attacker could possibly use this issue to corrupt
memory via a crafted HTML page, resulting in
GHSA
GHSA-fvmg-vwpf-h264: Inappropriate implementation in Internals in Google Chrome prior to 111
ghsa_unreviewed·2023-03-08
CVE-2023-1236 [MEDIUM] GHSA-fvmg-vwpf-h264: Inappropriate implementation in Internals in Google Chrome prior to 111
Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
OSV
CVE-2023-1236: Inappropriate implementation in Internals in Google Chrome prior to 111
osv·2023-03-07·CVSS 4.3
CVE-2023-1236 [MEDIUM] CVE-2023-1236: Inappropriate implementation in Internals in Google Chrome prior to 111
Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-07
Published