Описание
silverstripe/framework CSV Excel Macro Injection
In the CSV export feature of the CMS it's possible for the output to contain macros and scripts, which if imported without sanitisation into software (including Microsoft Excel) may be executed.
In order to safeguard against this threat all potentially executable cell values exported from CSV will be prepended with a literal tab character.
Ссылки
- https://github.com/silverstripe/silverstripe-framework/commit/55739fa5af6171594b2cb4f3621d5fcce5e887d4
- https://github.com/silverstripe/silverstripe-framework/commit/cfe1d4f481bf53ea8da2b8608a563e207d923df9
- https://github.com/silverstripe/silverstripe-framework/commit/dd4c5417e7592e29e698af428b72bdb9b6729797
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-007-1.yaml
- https://www.silverstripe.org/download/security-releases/ss-2017-007
Пакеты
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 3.5.0-rc1, < 3.5.6
3.5.6
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 3.6.0-rc1, < 3.6.3
3.6.3
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 4.0.0-rc1, < 4.0.1
4.0.1
8 High
CVSS3
Дефекты
CWE-74
8 High
CVSS3
Дефекты
CWE-74