CSV Injection Vulnerability in SAP Business One Data Export
CVE-2021-38180
9.8CRITICAL
What is CVE-2021-38180?
SAP Business One version 10.0 has a vulnerability that allows attackers to inject malicious formulas during data export to Excel files. This occurs due to inadequate sanitization of data exported in CSV format. If a victim opens the infected file and has macro execution enabled, the attacker could execute arbitrary commands on the victim's machine. It is crucial for users to exercise caution when opening CSV files from untrusted sources to mitigate this risk.
Affected Version(s)
SAP Business One < 10.0