CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
References
Link | Resource |
---|---|
https://github.com/kevinpapst/kimai2/commit/dad1b8b772947f1596175add1b4f33b791705507#diff-6774f5865dbaf8bc6c55b75bd92e6f9950ebe7834aa2efd828a19fd637e667cf | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-04-08T16:23:33
Updated: 2022-04-11T19:37:48
Reserved: 2021-11-08T00:00:00
Link: CVE-2021-43515
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-04-08T17:15:08.563
Modified: 2022-04-14T18:49:40.410
Link: CVE-2021-43515
JSON object: View
Redhat Information
No data.
CWE