Back to search
CVE-2018-15474
Published: Sep 7, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/splitbrain/dokuwiki/issues/2450
x_refsource_CONFIRM
20180906 SEC Consult SA-20180906-0 :: CSV Formula Injection in DokuWiki
mailing-list
x_refsource_FULLDISC
https://www.patreon.com/posts/unfixed-security-21250652
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now