Craft CMS before 3.7.14 allows CSV injection.
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Link | Tags |
---|---|
https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#3714---2021-09-28 | third party advisory release notes |
https://twitter.com/craftcmsupdates/status/1442928690145366018 | third party advisory |
https://github.com/craftcms/cms/security/advisories/GHSA-h7vq-5qgw-jwwq | third party advisory |