CVE-2020-5299: Potential CSV Injection vector in OctoberCMS

Published Jun 3, 2020
·
Updated

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the ImportExportController could potentially introduce a CSV injection into the data to cause the generated CSV export file to be malicious. This requires attackers to achieve the following before a successful attack can be completed: 1. Have found a vulnerability in the victims spreadsheet software of choice. 2. Control data that would potentially be exported through the ImportExportController by a theoretical victim. 3. Convince the victim to export above data as a CSV and run it in vulnerable spreadsheet software while also bypassing any sanity checks by said software. Issue has been patched in Build 466 (v1.0.466).

Affected Software

1 affected component
October CMS Debugbar>=1.0.319<1.0.466

Event History

Jun 3, 2020
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2020-5299?

CVE-2020-5299 is a vulnerability in OctoberCMS that allows users to introduce a CSV injection into exported data.

2

What is the severity of CVE-2020-5299?

CVE-2020-5299 has a severity rating of 5.1 (medium).

3

How does CVE-2020-5299 affect OctoberCMS?

CVE-2020-5299 affects OctoberCMS versions from 1.0.319 to 1.0.466.

4

How can an attacker exploit CVE-2020-5299?

An attacker can exploit CVE-2020-5299 by manipulating data that can be exported as a CSV file from the ImportExportController.

5

Is there a fix available for CVE-2020-5299?

Yes, a fix is available for CVE-2020-5299. It is recommended to update to version 1.0.466 or later of OctoberCMS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203