First published: Wed Mar 28 2018(Updated: )
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phlymail | <=5.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9107 is considered a medium severity vulnerability due to its potential for exploitation through CSV injection.
To fix CVE-2018-9107, you should upgrade the Acyba AcyMailing extension to version 5.9.6 or later.
Exploiting CVE-2018-9107 could allow an attacker to execute unauthorized commands when a malicious CSV file is opened in spreadsheet software.
CVE-2018-9107 affects AcyMailing versions prior to 5.9.6.
Yes, CVE-2018-9107 specifically affects the AcyMailing extension used within the Joomla! platform.