Skip to content

CSV injection (formula injection)

Low
anuko published GHSA-prjf-9mgh-8fpv Oct 15, 2020

Package

No package listed

Affected versions

<= 1.19.23.5324

Patched versions

1.19.23.5325

Description

Impact

Due to not properly filtered user input in versions prior to 1.19.23.5325 a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign).

Patches

Fixed in version 1.19.23.5325. Update Time Tracker to version 1.19.23.5325 or later,

Workarounds

No.

References

https://owasp.org/www-community/attacks/CSV_Injection

Severity

Low

CVE ID

CVE-2020-15255

Weaknesses

No CWEs

Credits