CSV Injection in iDempiere Web... Note

CSV Injection in iDempiere WebUI 12.0.0.202508171158

Posted by Ron E on Aug 18A CSV Injection vulnerability exists in iDempiere WebUI v12.0.0.202508171158. The application fails to properly sanitize user-supplied input before including it in exported CSV files. An authenticated attacker can inject malicious spreadsheet formulas (e.g., =cmd|'/C notepad'!A1) into fields that are later exported. When the CSV is opened in spreadsheet software such as Microsoft Excel or LibreOffice Calc, the injected formula is...