Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jqrp-58fv-w8cq | bagisto has CSV Formula Injection in Create New Product |
Wed, 22 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:webkul:bagisto:2.3.7:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webkul
Webkul bagisto |
|
| Vendors & Products |
Webkul
Webkul bagisto |
Fri, 17 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as a formula. This allows an attacker to supply a CSV field (e.g., product name) that contains a formula which may be evaluated by a victim’s spreadsheet application — potentially leading to data exfiltration and remote command execution (via older Excel exploits / OLE/cmd constructs or Excel macros). This vulnerability is fixed in 2.3.8. | |
| Title | bagisto - CSV Formula Injection in Create New Product | |
| Weaknesses | CWE-1236 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-17T14:32:48.820Z
Reserved: 2025-10-13T16:26:12.179Z
Link: CVE-2025-62417
Updated: 2025-10-17T14:32:39.693Z
Status : Analyzed
Published: 2025-10-16T19:15:34.650
Modified: 2025-10-22T17:00:09.873
Link: CVE-2025-62417
No data.
OpenCVE Enrichment
Updated: 2025-10-20T13:24:55Z
Github GHSA