CVE-2021-37702
EPSS 0.04%Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore
Published: 8/30/2021Modified: 3/13/2026
Also known as:GHSA-pp2h-95hm-hv9r
Description
### Impact Data Object CSV import allows formular injection. ### Patches Problem is patched in 10.1.1 ### Workarounds Apply https://github.com/pimcore/pimcore/pull/9992.patch ### References https://cwe.mitre.org/data/definitions/1236.html
Affected packages (1)
- Packagist/pimcore/pimcorefrom 0, < 10.1.1