vendor:
SilverStripe CMS
by:
Ishaq Mohammed
8,8
CVSS
HIGH
CSV Excel Macro Injection
94
CWE
Product Name: SilverStripe CMS
Affected Version From: 3.6.2
Affected Version To: 3.6.2
Patch Exists: YES
Related CWE: N/A
CPE: a:silverstripe:silverstripe_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2017
SilverStripe CMS – 3.6.2 CSV Excel Macro Injection
In the CSV export feature of the SilverStripe CMS, it's possible for the output to contain macros and scripts, which if imported without sanitization into software (including Microsoft Excel) may be executed.
Mitigation:
The issue has been fixed in the latest release of SilverStripe which can be downloaded from here: https://www.silverstripe.org/download