Skip to content

Potential formula injection in Excel/CSV export file

High
Molkobain published GHSA-9q3x-9987-53x9 Apr 15, 2024

Package

iTop (Sourceforge)

Affected versions

2.7.8, 3.0.3, 3.1.0

Patched versions

2.7.9, 3.0.4, 3.1.1, 3.2.0

Description

Impact

When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does not prevent Remote Code Execution by default, uninformed users may become victims.

Patches

An informative message is displayed in 2.7.9, 3.0.4, 3.1.1, 3.2.0

Workarounds

Excel prompts you with a warning when opening files with formulas, read the warning.
Correctly configure your Excel (see our documentation)

References

  • Combodo N°6951

Credits

Huge thanks to @0xKaiser for reporting this.

For more information

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

High
8.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE ID

CVE-2023-48709

Weaknesses

No CWEs

Credits