CVE-2020-25445
EUVD-2020-1813214.07.2021, 15:15
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bookingcore | booking_core | 1.7.0 |
𝑥
= Vulnerable software versions