CVE-2023-54348Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas into vendor name fields that execute on the workstation of users who open the exported CSV in a spreadsheet application. Attackers can add malicious formulas like =10+20+cmd|' /C calc'!A0 in the vendor creation form, which execute when the exported CSV file is opened in spreadsheet applications.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1236

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-05: 2Technical Details · 2026-05-05: 205-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2023-54348 ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute arbitrary code by injecting formula payloads into vendor name fie… https://www.cve.org/CVERecord?id=CVE-2023-54348

    Post summary

    The post discloses a CSV injection flaw in ERPGo SaaS 3.9 that permits authenticated attackers to run arbitrary code by injecting formulas into vendor names, but no proof‑of‑concept, exploit code or active use is reported.

    00010193
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2023-54348 ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute arbitrary code by injecting formula payloads into vendor name fie… https://www.cve.org/CVERecord?id=CVE-2023-54348 ----- Traducción: CVE-2023-54348 ERP… http://infoflow.cloud`

    Post summary

    The post discloses a CSV injection flaw in ERPGo SaaS 3.9, enabling authenticated attackers to run arbitrary code by injecting formulas into a vendor name field.

    0000042
    75 followersView on X

Explore more