PT-2026-5154 · Tendenci · Tendenci

Mufaddal Masalawala

·

Published

2026-01-28

·

Updated

2026-02-02

·

CVE-2020-36962

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tendenci version 12.3.1
Description The software contains a CSV formula injection issue in the contact form message field. This allows attackers to inject malicious formulas when a CSV file is exported. By submitting crafted payloads, such as '=10+20+cmd|' /C calc'!A0', within the message field, attackers can trigger arbitrary command execution when the CSV file is opened in spreadsheet applications. The vulnerable component is the message field within the contact form.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2020-36962
PYSEC-2026-136

Affected Products

Tendenci