Description
ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.
Problem types
Improper Neutralization of Formula Elements in a CSV File
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51517
www.exploit-db.com/exploits/51517 (ExploitDB-51517)
www.projectsend.org/ (Official Product Homepage)
www.vulncheck.com/...n-via-user-account-export-functionality (VulnCheck Advisory: ProjectSend r1605 CSV Injection via User Account Export Functionality)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.