
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-2112 is a vulnerability identified in GitHub repository inventree/inventree prior to version 0.7.2, involving Improper Neutralization of Formula Elements in a CSV File (NVD).
The vulnerability relates to improper sanitization of data in CSV file exports, specifically concerning formula injection attacks. The issue involves the handling of potentially malicious characters at the start of CSV fields, including '@', '=', '+', '-', '@', '\t', '\r', '\n' characters (GitHub Commit).
This vulnerability could potentially allow formula injection attacks through CSV files, which is a known attack vector that could lead to data manipulation or code execution when the exported CSV file is opened in spreadsheet applications (GitHub Commit).
The vulnerability was patched in InvenTree version 0.7.2. The fix includes implementing proper sanitization of CSV data by stripping potentially dangerous leading characters and implementing the InvenTreeResource class to handle CSV exports securely (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."