CSV Injection Affecting thorsten/phpmyfaq package, versions <2.9.11
Threat Intelligence
EPSS
0.1% (44th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-THORSTENPHPMYFAQ-72399
- published 16 Sep 2018
- disclosed 2 Sep 2018
- credit Zeel Chavda
Introduced: 2 Sep 2018
CVE-2018-16651 Open this link in a new tabHow to fix?
Upgrade thorsten/phpmyfaq to version 2.9.11 or higher.
Overview
thorsten/phpmyfaq is a FAQ system for PHP and MySQL, PostgreSQL and other databases
Affected versions of this package are vulnerable to CSV Injection. CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. When a spreadsheet program is used to open a CSV, any cells starting with '=' will be interpreted by the software as a formula. Maliciously crafted formulas can be used for three key attacks:
- Hijacking the user's computer by exploiting vulnerabilities in the spreadsheet software.
- Hijacking the user's computer by exploiting the user's tendency to ignore security warnings in spreadsheets that they downloaded from their own website
- Exfiltrating contents from the spreadsheet, or other open spreadsheets.
References
CVSS Scores
version 3.1