Improper Neutralization of Formula Elements in a CSV File in PrestaShop - #VU144207
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary formulas in a spreadsheet application.
The vulnerability exists due to improper neutralization of formula elements in a CSV file in CSV export files when opening exported CSV data in a spreadsheet application. A remote user can inject values beginning with formula characters into exported fields to execute arbitrary formulas in a spreadsheet application.
User interaction is required to open the exported CSV file in a spreadsheet application.