CWEBaseIncomplete20 recent CVEs

CWE-1236Improper Neutralization of Formula Elements in a CSV File

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Common consequences

Potential mitigations

Related CWEs

Recent CVEs classified under this CWE