{"id":"GHSA-3h6h-67x3-cv5x","summary":"Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications","details":"Description:\n\n### Summary\n\nPoweradmin v4.4.0 is vulnerable to CSV Injection (Formula Injection) in its log export functionality. User-controlled data — specifically the username field — is written to exported CSV files without sanitizing formula trigger characters (=, +, -, @). When an administrator exports activity logs and opens the resulting CSV in a spreadsheet application (Microsoft Excel, LibreOffice Calc, Google Sheets), any formula stored in a username is executed by the application. This can be used for phishing attacks against administrators or data exfiltration.\n\n### Details\n\nThe vulnerability exists in all four log export controllers:\n\n- `lib/Application/Controller/ListLogUsersController.php` (lines 188, 194)\n- `lib/Application/Controller/ListLogZonesController.php`\n- `lib/Application/Controller/ListLogGroupsController.php`\n- `lib/Application/Controller/ListLogApiController.php`\n\nThese controllers export database rows via `fputcsv()` without applying any formula injection countermeasures. The `user` column contains the username of the actor who performed the operation, and the `username` column (in user logs) contains the username of the affected account. Both fields are written verbatim to the CSV output.\n\nA username such as `=1+1` is written **without CSV enclosure quotes** (because it contains no commas or quotes), so spreadsheet applications treat it directly as a formula. A username containing commas or quotes (e.g. `=HYPERLINK(\"http://attacker.com\",\"Click here\")`) is enclosed in CSV quotes with internal quotes doubled, but spreadsheet applications still evaluate the cell value as a formula since it begins with `=`.\n\nAdditionally, PHP deprecation warnings are emitted directly into the HTTP response body before CSV headers, exposing internal file paths (e.g. `/app/lib/Application/Controller/ListLogUsersController.php`) — a secondary information disclosure issue (CWE-209). This also corrupts the CSV file when PHP error reporting is enabled.\n\n### PoC\n\n**Prerequisites:** An account with `user_add_new` permission (administrator role).\n\n**Steps to reproduce:**\n\n1. Log in as administrator.\n2. Navigate to Add User and create an account with:\n   - Username: `=HYPERLINK(\"http://attacker.com\",\"Confirm Identity\")`\n   - Any valid email and password\n3. Log out, then log in with the newly created account to generate a log entry.\n4. Log back in as administrator.\n5. Navigate to `/users/logs` and click Export CSV.\n6. Open the downloaded CSV file in Microsoft Excel or LibreOffice Calc.\n\n**Result:** Excel renders a clickable hyperlink labeled \"Confirm Identity\" pointing to `http://attacker.com` in the `user` column of the log entry. With the simpler username `=1+1`, the cell displays `2` instead of the literal text, confirming formula execution.\n\nConfirmed on Poweradmin v4.4.0 (Docker image `poweradmin/poweradmin:latest`).\n\n### Impact\n\nThis is a CSV Injection vulnerability (CWE-1236). It affects any administrator who exports activity logs to CSV and opens the file in a spreadsheet application.\n\n**Attack scenarios:**\n\n- **Phishing:** A malicious actor with the ability to create user accounts sets a formula username that renders as a convincing link in the exported report, tricking a higher-privileged administrator into clicking it.\n- **Data exfiltration:** Using `=IMPORTXML()` in Google Sheets or similar, adjacent cell data (log contents) can be sent to an attacker-controlled server silently when the sheet is opened.","aliases":["CVE-2026-47693"],"modified":"2026-09-10T03:50:55.279858235Z","published":"2026-06-08T23:04:25Z","database_specific":{"nvd_published_at":"2026-06-23T23:16:49Z","cwe_ids":["CWE-1236"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-08T23:04:25Z"},"references":[{"type":"WEB","url":"https://github.com/poweradmin/poweradmin/security/advisories/GHSA-3h6h-67x3-cv5x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47693"},{"type":"PACKAGE","url":"https://github.com/poweradmin/poweradmin"},{"type":"WEB","url":"https://github.com/poweradmin/poweradmin/releases/tag/v4.2.4"},{"type":"WEB","url":"https://github.com/poweradmin/poweradmin/releases/tag/v4.3.3"}],"affected":[{"package":{"name":"poweradmin/poweradmin","ecosystem":"Packagist","purl":"pkg:composer/poweradmin/poweradmin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.4"}]}],"versions":["v2.1.8","v2.1.9","v2.2.0","v2.2.1","v2.2.2","v3.0.0","v3.1.0","v3.2.0","v3.3.0","v3.4.0","v3.4.1","v3.4.2","v3.5.0","v3.5.1","v3.6.0","v3.6.1","v3.7.0","v3.7.0-alpha.1","v3.8.0","v3.8.1","v3.9.0","v3.9.1","v3.9.10","v3.9.11","v3.9.12","v3.9.2","v3.9.3","v3.9.4","v3.9.5","v3.9.6","v3.9.7","v3.9.8","v3.9.9","v4.0.0","v4.0.1","v4.0.10","v4.0.11","v4.0.2","v4.0.3","v4.0.4","v4.0.5","v4.0.6","v4.0.7","v4.0.9","v4.1.0","v4.1.1","v4.1.2","v4.1.3","v4.1.4","v4.2.0","v4.2.1","v4.2.2","v4.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3h6h-67x3-cv5x/GHSA-3h6h-67x3-cv5x.json"}},{"package":{"name":"poweradmin/poweradmin","ecosystem":"Packagist","purl":"pkg:composer/poweradmin/poweradmin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0"},{"fixed":"4.3.3"}]}],"versions":["v4.3.0","v4.3.1","v4.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3h6h-67x3-cv5x/GHSA-3h6h-67x3-cv5x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N"}]}