CVE Vulnerabilities

CVE-2022-40294

Improper Neutralization of Formula Elements in a CSV File

Published: Oct 31, 2022 | Modified: May 06, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.

Weakness

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Affected Software

NameVendorStart VersionEnd Version
Php_point_of_salePhppointofsale19.0 (including)19.0 (including)

Potential Mitigations

References