PT-2021-15542 · Unknown · Html-To-Csv

0Xbughunter

·

Published

2021-11-26

·

Updated

2021-12-20

·

CVE-2021-23654

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions html-to-csv versions all
Description The issue arises when a formula is embedded in an HTML page and gets accepted without validation, allowing it to be pushed into a CSV file during conversion. This enables a malicious actor to embed or generate malicious links or execute commands via CSV files.
Recommendations For all versions, consider disabling the conversion of HTML pages with embedded formulas to CSV files until a proper validation mechanism is implemented to prevent malicious links or command execution. Restrict access to the CSV file generation feature to minimize the risk of exploitation. Avoid using the html-to-csv package for converting HTML pages with embedded formulas until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23654
GHSA-FWF6-RW69-HHJ4
PYSEC-2021-866
SNYK-PYTHON-HTMLTOCSV-1582784

Affected Products

Html-To-Csv