CSV Injection with the CSV export feature
Low
W
Weblate
Submitted None
Actions:
Reported by
jaypatel
Vulnerability Details
Technical details and impact analysis
**Step to reproduce :**
1.go to https://hosted.weblate.org/dictionaries/aptoide-uploader/bn/#add
2.add "=1+1" to **Source** and ** Translation** filed
{F178723}
3.now do **CSV export**
4.you can see all the cell is displayed as "2" which means the code is executed.
Best Regad's,
Jay Patel
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
OS Command Injection