Junglewise Threat Intelligence

CVE-2023-2629: Embedding untrusted input inside CSV files leads to Formula Injection/CSV Injection

CVE-2023-2629 · Severity: low · CVSS 3.1 · Published 2023-05-11

Technologies: pimcore/customer-management-framework-bundle (Packagist). Vendors: Packagist.

Executive brief

Embedding untrusted input inside CSV files leads to Formula Injection/CSV Injection

Affected products

  • Packagist pimcore/customer-management-framework-bundle

Related threats