CVE Vulnerabilities

CVE-2022-41675

Improper Neutralization of Formula Elements in a CSV File

Published: Nov 29, 2022 | Modified: Dec 01, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow the attacker to perform arbitrary system operation or disrupt service on the user side.

Weakness

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Affected Software

Name Vendor Start Version End Version
Raidenmaild Raidenmaild * 4.7.4 (excluding)

Potential Mitigations

References