CVE-2023-53913
17.12.2025, 23:15
Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.Enginsight
| Vendor | Product | Version |
|---|---|---|
| rukovoditel | rukovoditel | 3.3.1 |
𝑥
= Vulnerable software versions