Логотип exploitDog
bind:CVE-2017-18049
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-18049

Количество 2

Количество 2

nvd логотип

CVE-2017-18049

около 8 лет назад

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jvj-mhf2-g99w

больше 3 лет назад

SilverStripe CSV Excel Macro Injection

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-18049

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.

CVSS3: 5.5
0%
Низкий
около 8 лет назад
github логотип
GHSA-2jvj-mhf2-g99w

SilverStripe CSV Excel Macro Injection

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу