CVE-2023-3302: Improper Neutralization of Formula Elements in a CSV File in admidio/admidio
Admidio prior to 4.2.9 is vulnerable toImproper Neutralization of Formula Elements in a CSV File.
Other sources
Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/admidio/admidioto a version that resolves this vulnerability.Fixed in 4.2.9
Event History
Frequently Asked Questions
What is CVE-2023-3302?
CVE-2023-3302 is a vulnerability that allows for improper neutralization of formula elements in a CSV file.
What software versions are affected by CVE-2023-3302?
Admidio versions prior to 4.2.9 are affected by CVE-2023-3302.
What is the severity of CVE-2023-3302?
CVE-2023-3302 has a severity rating of 7.8 (high).
How can I fix CVE-2023-3302?
To fix CVE-2023-3302, you should update Admidio to version 4.2.9 or later.
Where can I find more information about CVE-2023-3302?
You can find more information about CVE-2023-3302 at the following references: [GitHub commit](https://github.com/admidio/admidio/commit/c87a7074a1a73c4851263060afd76aa4d5b6415f), [Huntr bounty](https://huntr.dev/bounties/5e18619f-8379-464a-aad2-65883bb4e81a), [NVD entry](https://nvd.nist.gov/vuln/detail/CVE-2023-3302).