Vulnerability Description
SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to execute macros while opening the file and the security settings of Excel allow for command execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business One | 10.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3079427Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3079427Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
FAQ
What is CVE-2021-38180?
CVE-2021-38180 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute...
How severe is CVE-2021-38180?
CVE-2021-38180 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-38180?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Business One.