{"id":"GHSA-7rq4-qcpw-74gq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7rq4-qcpw-74gq","summary":"Formula Injection in Exported Data","details":"### Impact\n\nDatasets exported to file (e.g. CSV / XLS) are not sufficiently sanitized, to neutralize potential formula injection\n\n### Patches\n\n- The issue is addressed in the upcoming 0.8.0 release\n- This fix will also be back-ported to the 0.7.x branch, applied to the 0.7.2 release\n\n### Workarounds\n\nUsers exporting untrusted data should open the files in safe mode (e.g. in Microsoft Excel).\n\n### References\n\n- https://huntr.dev/bounties/e57c36e7-fa39-435f-944a-3a52ee066f73/\n- https://owasp.org/www-community/attacks/CSV_Injection\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [github](http://github.com/inventree/inventree)\n* Email us at [security@inventree.org](mailto:security@inventree.org)\n","published":"2022-06-17T01:17:22Z","modified":"2024-12-08T05:27:25.214106Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"inventree","fixedVersion":"0.7.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-7rq4-qcpw-74gq"},{"type":"WEB","url":"https://github.com/inventree/inventree-python"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-08T05:27:25.214106Z"}}