vendor:
Siebel CRM
by:
Sarath Nair aka AceNeon13
7.5
CVSS
HIGH
CSV Injection
78
CWE
Product Name: Siebel CRM
Affected Version From: Oracle Siebel CRM Version 8.1.1 and below
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2018
Oracle Siebel CRM 8.1.1 – CSV Injection
Siebel CRM application was found to be vulnerable to Excel Macro injection vulnerability, in places where user input is allowed (in text form) and the input can then be exported in CSV form. An attacker can change user information to include in his input a malicious excel function. The function will then be executed on the victim’s machine, once the victim exports the details in CSV format and opens the exported file in Microsoft Excel.
Mitigation:
Disable CSV export in all list applets and where CSV export is available.