Collected research
The Absurdly Underestimated Dangers of CSV Injection
A cell that an ordinary user plants in an application, beginning with an equals, plus, minus or at sign, is evaluated as a formula when an administrator opens the CSV export. Excel DDE payloads run commands on the administrator machine, and a Google Sheets IMPORTXML formula silently posts their rows, and other spreadsheets they can read, to the attacker server.
Record
- Published by
- georgemauer.net
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of georgemauer.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .