Keystone is vulnerable to CSV injection
High severity
GitHub Reviewed
Published
Nov 16, 2017
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Nov 16, 2017
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.
References