What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in Pär Thernström Simple History – user activity log, audit tool.This issue affects Simple History – user activity log, audit tool: from n/a through 3.3.1.
Explanation of Vulnerability in Simple Terms
02Summary
Simple History versions up to 3.3.1 contain an integrity vulnerability allowing authenticated users with low privileges to modify site content through a cross-site request forgery (CSRF) attack. The attacker must trick a logged-in administrator into visiting a malicious page. No confidentiality or availability impact occurs. Update to a version newer than 3.3.1.
What an attacker can do
03Attacker Capabilities
Modify site content or settings if a logged-in admin visits an attacker-controlled page.
Potential impact on your site
04Site Impact
An attacker with low-privilege access can alter site data if they trick an admin into visiting a crafted page.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege account; victim (admin) must click a malicious link or visit attacker's page.
Key dates
06Disclosure timeline
November 7, 2023
CVE published
April 28, 2026
Record updated