CVE-2017-15879
24.10.2017, 21:29
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.Enginsight
Vendor | Product | Version |
---|---|---|
keystonejs | keystone | 𝑥 ≤ 4.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References