PT-2021-21989 · Microsoft+1 · Office Excel+1
Published
2021-10-12
·
Updated
2021-10-19
·
CVE-2021-38180
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SAP Business One version 10.0
Description:
The issue allows an attacker to inject formulas when exporting data to Excel due to improper sanitation during the data export, which can lead to the execution of arbitrary commands on the victim's computer. This is possible only if the victim allows macro execution while opening the file and the security settings of Excel permit command execution.
Recommendations:
For SAP Business One version 10.0, consider disabling the export to Excel feature until a patch is available to prevent CSV injection attacks. Additionally, users should be cautious when opening Excel files and avoid enabling macro execution unless necessary, and review their Excel security settings to restrict command execution.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Excel
Sap Business One