CVE-2020-25445

The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bookingcore:booking_core:1.7.0:*:*:*:*:*:*:*

History

07 Nov 2023, 03:20

Type Values Removed Values Added
References
  • {'url': 'https://medium.com/@singh.satyam158/vulnerabilities-in-booking-core-1-7-d85d1dfae44e', 'name': 'https://medium.com/@singh.satyam158/vulnerabilities-in-booking-core-1-7-d85d1dfae44e', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://medium.com/%40singh.satyam158/vulnerabilities-in-booking-core-1-7-d85d1dfae44e -

16 Jul 2021, 20:23

Type Values Removed Values Added
CPE cpe:2.3:a:bookingcore:booking_core:1.7.0:*:*:*:*:*:*:*
CWE CWE-1236
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
References (MISC) https://medium.com/@singh.satyam158/vulnerabilities-in-booking-core-1-7-d85d1dfae44e - (MISC) https://medium.com/@singh.satyam158/vulnerabilities-in-booking-core-1-7-d85d1dfae44e - Exploit, Third Party Advisory

14 Jul 2021, 20:15

Type Values Removed Values Added
Summary Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0. The “Subscribe” feature of the application is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result, when an admin in the backend downloads and opens the CSV, the content of the cells is executed. Vulnerable fields: First name and Last name of the “Subscribe” request. The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.

14 Jul 2021, 15:52

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-14 15:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-25445

Mitre link : CVE-2020-25445

CVE.ORG link : CVE-2020-25445


JSON object : View

Products Affected

bookingcore

  • booking_core
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File