Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2017-18049

больше 8 лет назад

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jvj-mhf2-g99w

около 4 лет назад

SilverStripe CSV Excel Macro Injection

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-18049

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.

CVSS3: 5.5
1%
Низкий
больше 8 лет назад
github логотип
GHSA-2jvj-mhf2-g99w

SilverStripe CSV Excel Macro Injection

CVSS3: 5.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу