CVE Vulnerabilities

CVE-2024-24337

Improper Neutralization of Formula Elements in a CSV File

Published: Feb 12, 2024 | Modified: Sep 29, 2025
CVSS 3.x
8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CSV Injection vulnerability in /members/moremember.pl and /admin/aqbudgets.pl endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the Budget and Patrons Member components.

Weakness

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Affected Software

NameVendorStart VersionEnd Version
KohaKoha*23.05.05 (including)

Potential Mitigations

References