CVE-2017-18049

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-18049
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18049.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-18049
Aliases
Published
2018-01-23T06:29:00Z
Modified
2024-09-03T01:48:02.209754Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.

References

Affected packages

Git / github.com/silverstripe/silverstripe-cms

Affected ranges

Type
GIT
Repo
https://github.com/silverstripe/silverstripe-cms
Events
Type
GIT
Repo
https://github.com/silverstripe/silverstripe-framework
Events

Affected versions

3.*

3.4.6
3.5.4
3.5.5
3.5.5-beta1
3.5.5-beta2
3.6.0
3.6.1
3.6.1-alpha1
3.6.1-alpha2
3.6.2
3.6.2-beta1
3.6.2-beta2

4.*

4.0.0
4.0.0-alpha1
4.0.0-alpha2
4.0.0-alpha3
4.0.0-alpha4
4.0.0-alpha5
4.0.0-alpha6
4.0.0-alpha7
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-rc1
4.0.0-rc2
4.0.0-rc3