vendor:
Acymailing Starter
by:
Sureshbabu Narvaneni
8.8
CVSS
HIGH
CSV Injection
20
CWE
Product Name: Acymailing Starter
Affected Version From: 5.9.5
Affected Version To: 5.9.6
Patch Exists: YES
Related CWE: CVE-2018-9107
CPE: a:acyba:acymailing_starter
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 14.04 x86_64/Kali Linux 4.12 i686
2018
Joomla! Component Acymailing Starter 5.9.5 CSV Macro Injection
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export. Login as low privileged user who is having access to Acymailing Component. Rename user name as @SUM(1+1)*cmd|' /C calc'!A0. When high privileged user logged in and exported user data then the CSV Formula gets executed and calculator will get popped in his machine.
Mitigation:
Upgrade to version 5.9.6