CVE-2023-53905: ProjectSend r1605 CSV Injection via User Account Export Functionality
ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53905?
CVE-2023-53905 is classified as a medium severity vulnerability due to its potential for exploitation through CSV injection by authenticated users.
How do I fix CVE-2023-53905?
To fix CVE-2023-53905, ensure that input validation and sanitization are applied to user profile names to prevent malicious formula injection.
Who is affected by CVE-2023-53905?
Any user of ProjectSend r1605 who allows authenticated users to create or modify profile names is potentially affected by CVE-2023-53905.
What type of attack is CVE-2023-53905?
CVE-2023-53905 is a CSV injection vulnerability that allows the execution of malicious payloads through exported CSV files.
What versions of ProjectSend are impacted by CVE-2023-53905?
CVE-2023-53905 impacts ProjectSend in version r1605.