CSV Injection in ProjectSend Affects Data Importing to Microsoft Excel
CVE-2018-7201

8.8HIGH

Key Information:

Vendor
CVE Published:
22 May 2019

What is CVE-2018-7201?

A CSV Injection vulnerability was identified in ProjectSend prior to version r1053. This flaw poses risks for users who import CSV data into Microsoft Excel, potentially allowing attackers to manipulate data and execute unauthorized actions within Excel. It is crucial for users of affected versions to update to the latest release to mitigate these risks and ensure data integrity.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.