Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Link | Tags |
---|---|
https://huntr.dev/bounties/5e18619f-8379-464a-aad2-65883bb4e81a | patch third party advisory exploit |
https://github.com/admidio/admidio/commit/c87a7074a1a73c4851263060afd76aa4d5b6415f | patch |