CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Link | Tags |
---|---|
https://www.acyba.com/acymailing/change-log.html | vendor advisory |
https://www.exploit-db.com/exploits/44369/ | exploit vdb entry third party advisory |
https://vel.joomla.org/resolved/2136-acymailing-5-9-5-csv-injection | third party advisory |
https://vel.joomla.org/articles/2140-introducing-csv-injection | third party advisory |