Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q3w-jgfx-4792

Опубликовано: 28 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 9.8

Описание

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when the CSV is opened in spreadsheet applications.

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when the CSV is opened in spreadsheet applications.

EPSS

Процентиль: 39%
0.00176
Низкий

5.3 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 9.8
nvd
11 дней назад

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when the CSV is opened in spreadsheet applications.

EPSS

Процентиль: 39%
0.00176
Низкий

5.3 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1236