{"id":"CVE-2017-18049","details":"In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the \"First Name\" field of a user's /myprofile page.","aliases":["GHSA-2jvj-mhf2-g99w"],"modified":"2026-08-07T14:49:14.216321Z","published":"2018-01-23T06:29:00.277Z","references":[{"type":"ADVISORY","url":"https://www.silverstripe.org/download/security-releases/ss-2017-007"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/43396/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/silverstripe/silverstripe-cms","events":[{"introduced":"0"},{"last_affected":"5512711471e48e9f759e386fedcdb1bc63e555e8"},{"introduced":"08093ea308c13f1f334a01b46d66b720bd86216e"},{"last_affected":"a308ab327bf6bcc9a3d1f1cd36cffc3850e014b5"},{"introduced":"0c02b8872f29a1c789d3313562cde6117892d9c7"},{"last_affected":"0c02b8872f29a1c789d3313562cde6117892d9c7"}],"database_specific":{"cpe":["cpe:2.3:a:silverstripe:silverstripe:*:*:*:*:*:*:*:*","cpe:2.3:a:silverstripe:silverstripe:4.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"3.5.5"},{"introduced":"3.6.0"},{"last_affected":"3.6.2"},{"introduced":"4.0.0"},{"last_affected":"4.0.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["4.0.0","4.0.0-rc3","3.6.2-beta2","3.6.2-beta1","3.6.2","3.5.5-beta1","3.5.5","3.6.1-alpha1","3.6.0-beta1","3.5.3-rc1","3.5.2-rc1","3.5.2","3.5.0-rc2","3.5.0-rc1","3.0.0-rc1","3.0.0-beta3","3.0.0-beta2","3.0.0-beta1","3.0.0-alpha2","3.0.0-alpha1","HamishsTesta2","3.0.0-pr1","2.3.0-rc1","2.2.2-rc1","2.2.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18049.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/silverstripe/silverstripe-framework","events":[{"introduced":"0"},{"last_affected":"393d1a9be6b1eb6da40929b58b2b75c911d7c0c2"},{"introduced":"143c4a63cf1f7cf5697abbe31908e446ed2ecb3e"},{"last_affected":"3f5ddc7d003920a3f4bd65a33ce1150fbe4ee60e"},{"introduced":"6d8df46b8a7e3281fbd1299c626dd7a5a9a14a83"},{"last_affected":"6d8df46b8a7e3281fbd1299c626dd7a5a9a14a83"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"3.5.5"},{"introduced":"3.6.0"},{"last_affected":"3.6.2"},{"introduced":"4.0.0"},{"last_affected":"4.0.0"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:silverstripe:silverstripe:*:*:*:*:*:*:*:*","cpe:2.3:a:silverstripe:silverstripe:4.0.0:*:*:*:*:*:*:*"]}}],"versions":["4.0.0","3.6.2","3.5.5","3.6.2-beta2","3.5.5-beta2","3.5.5-beta1","3.6.2-beta1","3.6.0-beta1","3.5.3-rc1","3.5.2-rc1","3.5.0-rc2","3.5.0-rc1","3.0.0-rc1","3.0.0-beta3","3.0.0-beta2","3.0.0-beta1","3.0.0-alpha2","3.0.0-alpha1","2.2.2-rc1","2.3.0-rc1","2.2.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18049.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}