漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
bagisto - CSV Formula Injection in Create New Product
Vulnerability Description
Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as a formula. This allows an attacker to supply a CSV field (e.g., product name) that contains a formula which may be evaluated by a victim’s spreadsheet application — potentially leading to data exfiltration and remote command execution (via older Excel exploits / OLE/cmd constructs or Excel macros). This vulnerability is fixed in 2.3.8.
CVSS Information
N/A
Vulnerability Type
CWE-1236
Vulnerability Title
Webkul Software Bagisto 安全漏洞
Vulnerability Description
Webkul Software Bagisto是印度Webkul Software公司的一套开源的电子商务框架。 Webkul Software Bagisto 2.3.8之前版本存在安全漏洞,该漏洞源于未正确处理电子表格公式字符,可能导致数据渗漏和远程命令执行。
CVSS Information
N/A
Vulnerability Type
N/A