Description
This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV file. Through this a malicious actor can embed or generate a malicious link or execute commands via CSV files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0097 | This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV file. Through this a malicious actor can embed or generate a malicious link or execute commands via CSV files. |
Github GHSA |
GHSA-fwf6-rw69-hhj4 | Improper Neutralization of Formula Elements in a CSV File in html-2-csv |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T17:43:55.862Z
Reserved: 2021-01-08T00:00:00.000Z
Link: CVE-2021-23654
No data.
Status : Modified
Published: 2021-11-26T20:15:07.393
Modified: 2024-11-21T05:51:51.487
Link: CVE-2021-23654
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA