CSV Injection via the CSV export feature

Disclosed: 2016-04-25 10:37:54 By stewie To security
Unknown
Vulnerability Details
I've bypassed #111192 by using this string ";=cmd|' /C calc'!A0" without doublequotes. Steps to reproduce are as in #111192. Tested in excel 2003-2013
Actions
View on HackerOne
Report Stats
  • Report ID: 124223
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report