CVE-2021-37702

EPSS 0.04%

Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore

Published: 8/30/2021Modified: 3/13/2026
Also known as:GHSA-pp2h-95hm-hv9r

Description

### Impact Data Object CSV import allows formular injection. ### Patches Problem is patched in 10.1.1 ### Workarounds Apply https://github.com/pimcore/pimcore/pull/9992.patch ### References https://cwe.mitre.org/data/definitions/1236.html

Affected packages (1)

References (4)