Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23246 | Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed. |
Wed, 06 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:alfasado:powercms:*:*:*:*:*:*:*:* |
Thu, 31 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alfasado
Alfasado powercms |
|
| Vendors & Products |
Alfasado
Alfasado powercms |
Thu, 31 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 31 Jul 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed. | |
| Weaknesses | CWE-1236 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-07-31T15:44:45.539Z
Reserved: 2025-07-30T05:36:44.305Z
Link: CVE-2025-54752
Updated: 2025-07-31T15:39:28.919Z
Status : Analyzed
Published: 2025-07-31T08:15:25.300
Modified: 2025-08-06T16:41:58.223
Link: CVE-2025-54752
No data.
OpenCVE Enrichment
Updated: 2025-07-31T20:56:24Z
EUVD