PT-2021-15542 · Unknown · Html-To-Csv
0Xbughunter
·
Published
2021-11-26
·
Updated
2021-12-20
·
CVE-2021-23654
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
html-to-csv versions all
Description
The issue arises when a formula is embedded in an HTML page and gets accepted without validation, allowing it to be pushed into a CSV file during conversion. This enables a malicious actor to embed or generate malicious links or execute commands via CSV files.
Recommendations
For all versions, consider disabling the conversion of HTML pages with embedded formulas to CSV files until a proper validation mechanism is implemented to prevent malicious links or command execution. Restrict access to the CSV file generation feature to minimize the risk of exploitation. Avoid using the html-to-csv package for converting HTML pages with embedded formulas until the issue is resolved.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Html-To-Csv