Skip to main content

This site requires you to update your browser. Your browsing experience maybe affected by not having the most up to date version.

SS-2017-007: CSV Excel Macro Injection

Severity:
Low (?)
Identifier:
ss-2017-007
Versions Affected:
3.5.5 and below, 3.6.0 to 3.6.2, 4.0.0
Versions Fixed:
3.5.6, 3.6.3, 4.0.1
Release Date:
2017-12-07

In the CSV export feature of the CMS it's possible for the output to contain macros and scripts, which if imported without sanitisation into software (including Microsoft Excel) may be executed.

In order to safeguard against this threat all potentially executable cell values exported from CSV will be prepended with a literal tab character.

Reported by Ishaq Mohammed