Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when the CSV is opened in spreadsheet applications.
References
| Link | Resource |
|---|---|
| https://github.com/tendenci/tendenci | Product |
| https://www.exploit-db.com/exploits/49145 | Exploit Third Party Advisory VDB Entry |
| https://www.tendenci.com/ | Product |
| https://www.vulncheck.com/advisories/tendenci-csv-formula-injection | Third Party Advisory |
| https://www.exploit-db.com/exploits/49145 | Exploit Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2026-01-28 18:16
Updated : 2026-02-02 19:13
NVD link : CVE-2020-36962
Mitre link : CVE-2020-36962
CVE.ORG link : CVE-2020-36962
JSON object : View
Products Affected
tendenci
- tendenci
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
