
CVE-2023-54348 ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute arbitrary code by injecting formula payloads into vendor name fie… https://www.cve.org/CVERecord?id=CVE-2023-54348
Post summary
The post discloses a CSV injection flaw in ERPGo SaaS 3.9 that permits authenticated attackers to run arbitrary code by injecting formulas into vendor names, but no proof‑of‑concept, exploit code or active use is reported.

