PT-2021-21989 · Microsoft+1 · Office Excel+1

Published

2021-10-12

·

Updated

2021-10-19

·

CVE-2021-38180

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SAP Business One version 10.0
Description: The issue allows an attacker to inject formulas when exporting data to Excel due to improper sanitation during the data export, which can lead to the execution of arbitrary commands on the victim's computer. This is possible only if the victim allows macro execution while opening the file and the security settings of Excel permit command execution.
Recommendations: For SAP Business One version 10.0, consider disabling the export to Excel feature until a patch is available to prevent CSV injection attacks. Additionally, users should be cautious when opening Excel files and avoid enabling macro execution unless necessary, and review their Excel security settings to restrict command execution.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38180

Affected Products

Office Excel
Sap Business One