CSV Injection Vulnerability in SAP Business One Data Export
CVE-2021-38180

9.8CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 October 2021

Summary

SAP Business One version 10.0 has a vulnerability that allows attackers to inject malicious formulas during data export to Excel files. This occurs due to inadequate sanitization of data exported in CSV format. If a victim opens the infected file and has macro execution enabled, the attacker could execute arbitrary commands on the victim's machine. It is crucial for users to exercise caution when opening CSV files from untrusted sources to mitigate this risk.

Affected Version(s)

SAP Business One < 10.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.