KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Link | Tags |
---|---|
https://gist.github.com/6en6ar/5d39374d6ced8acbe489e0b1b932d056 | third party advisory |