CVE-2023-53905

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:projectsend:projectsend:r1605:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-17 23:15

Updated : 2025-12-27 17:15


NVD link : CVE-2023-53905

Mitre link : CVE-2023-53905

CVE.ORG link : CVE-2023-53905


JSON object : View

Products Affected

projectsend

  • projectsend
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File