cve/2022/CVE-2022-22121.md

18 lines
848 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-22121](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22121)
![](https://img.shields.io/static/v1?label=Product&message=nocodb&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3E%3D%200.81.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-1236&color=brighgreen)
### Description
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a CSV file and opens it, the payload gets executed.
### POC
#### Reference
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22121
#### Github
No PoCs found on GitHub currently.