← Back to CVE List

CVE-2020-25445

Published: 2021-07-14T15:15Z
Last Modified: 2024-11-21T05:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt