First published: Thu Apr 14 2022(Updated: )
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | <2.25.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43257 is a vulnerability in the CSV API of MantisBT before version 2.25.3 that allows an unprivileged attacker to execute code or gain access to information when a user opens the generated CSV file in Excel.
CVE-2021-43257 has a severity score of 7.8, which is considered high.
CVE-2021-43257 affects MantisBT versions up to and excluding 2.25.3.
An attacker can exploit CVE-2021-43257 by crafting a malicious CSV file and tricking a user into opening it in Excel.
Yes, you can find more information about CVE-2021-43257 in the MantisBT commit at https://github.com/mantisbt/mantisbt/commit/7f4534c723e3162b8784aebda4836324041dbc3e and the MantisBT bug report at https://www.mantisbt.org/bugs/view.php?id=29130.