Top 10 winner
Data Exfiltration via Formula Injection #Part1
Spreadsheet formulas planted in imported CSV data run when the sheet is opened, and built-in functions that fetch remote resources carry data out of band. In Google Sheets IMPORTXML and friends exfiltrate other users' form responses; in LibreOffice on Linux, file:// cell references plus WEBSERVICE read local files and leak them over HTTP or DNS.
Record
- Researcher
- Ajay and Balaji
- Published by
- NotSoSecure
- Date
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ajay and Balaji, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .