CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-07T22:00:00

Updated: 2020-02-24T21:57:10

Reserved: 2018-08-17T00:00:00


Link: CVE-2018-15474

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-09-07T22:29:00.977

Modified: 2024-05-17T01:24:18.733


Link: CVE-2018-15474

JSON object: View

cve-icon Redhat Information

No data.

CWE