What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in Shambix Simple CSV/XLS Exporter.This issue affects Simple CSV/XLS Exporter: from n/a through 1.5.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
What the vulnerability does
Improper Neutralization of Formula Elements in a CSV File vulnerability in Shambix Simple CSV/XLS Exporter.This issue affects Simple CSV/XLS Exporter: from n/a through 1.5.8.
Explanation of Vulnerability in Simple Terms
Simple CSV/XLS Exporter versions up to 1.5.8 contain an integrity vulnerability that allows a low-privileged user to modify data through a crafted request. The attack requires user interaction and affects the integrity of exported files. The scope is changed, meaning the impact may extend beyond the vulnerable component itself.
What an attacker can do
Modify exported CSV/XLS file contents or structure through a crafted request.
Potential impact on your site
Exported data files may be corrupted or contain unauthorized modifications by low-privilege users.
Conditions required to exploit
Low-privilege user account and victim must interact with a malicious link or request.
Key dates
External resources
Related vulnerabilities