CVE-2021-43257: High severity centos libreport-plugin-mantisbt vulnerability
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csvexport.php generated CSV file in Excel.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-43257?
CVE-2021-43257 is a vulnerability in the CSV API of MantisBT before version 2.25.3 that allows an unprivileged attacker to execute code or gain access to information when a user opens the generated CSV file in Excel.
How severe is CVE-2021-43257?
CVE-2021-43257 has a severity score of 7.8, which is considered high.
Which software versions are affected by CVE-2021-43257?
CVE-2021-43257 affects MantisBT versions up to and excluding 2.25.3.
How can an attacker exploit CVE-2021-43257?
An attacker can exploit CVE-2021-43257 by crafting a malicious CSV file and tricking a user into opening it in Excel.
Are there any references for CVE-2021-43257?
Yes, you can find more information about CVE-2021-43257 in the MantisBT commit at https://github.com/mantisbt/mantisbt/commit/7f4534c723e3162b8784aebda4836324041dbc3e and the MantisBT bug report at https://www.mantisbt.org/bugs/view.php?id=29130.