PT-2023-31887 · Unknown · Activeadmin
Mgrunberg
·
Published
2023-12-23
·
Updated
2024-01-03
·
CVE-2023-51763
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ActiveAdmin versions prior to 3.2.0
Description
The issue allows CSV injection, which can lead to remote code execution and private data exfiltration when maliciously crafted spreadsheet formulas are uploaded and imported into a spreadsheet program. The attacker needs privileges to upload data and the victim must ignore security warnings from their spreadsheet program.
Recommendations
For versions prior to 3.2.0, update to version 3.2.0 or above, which fixes the problem by escaping any data starting with
= and other characters used by spreadsheet programs.
As a temporary workaround, consider only turning on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Activeadmin