CVE-2020-25445
14.07.2021, 15:15
The Subscribe feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.Enginsight
Vendor | Product | Version |
---|---|---|
bookingcore | booking_core | 1.7.0 |
𝑥
= Vulnerable software versions