CVE-2018-9107
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.
- Affected products
- Acymailing
- Acyba Acymailing
- ≤ 5.9.5
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 7.2% (94th percentile)
- Weakness
- CWE-1236
- NVD status
- Modified
- Published
- 2018-03-28
CVE-2018-9107 at NVD
4 known exploits for CVE-2018-9107
Proof-of-concept code and exploit modules indexed by Sploitus