
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53929 is a CSV injection vulnerability (also known as formula injection) in phpMyFAQ version 3.1.12 that allows authenticated low-privilege users to inject malicious spreadsheet formulas into their user profile names. When an administrator exports user data as a CSV file, the injected formulas can be executed by the spreadsheet application processing the file, potentially leading to arbitrary code execution on the administrator's system. The vulnerability was published on December 17, 2025, and carries a CVSS v3.1 base score of 8.0 (High) (Red Hat Advisory, VulnCheck Advisory).
The root cause is classified as CWE-1236 (Improper Neutralization of Formula Elements in a CSV File). phpMyFAQ 3.1.12 fails to sanitize user-controlled input — specifically the profile name field — before including it in administrator-generated CSV exports. An authenticated attacker can set their profile name to a payload such as =calc|a!z| or similar formula strings that spreadsheet applications (e.g., Microsoft Excel, LibreOffice Calc) interpret as executable formulas upon file open. Exploitation requires the attacker to have a valid (low-privilege) account and relies on an administrator subsequently exporting user data to CSV. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB PoC, VulnCheck Advisory).
Successful exploitation results in arbitrary code execution on the machine of the administrator who opens the exported CSV file, not directly on the server. This can lead to full compromise of the administrator's workstation, including confidentiality loss (credential theft, data exfiltration), integrity loss (file modification, malware installation), and availability impact. Because administrators typically have elevated access to the phpMyFAQ application and potentially broader network resources, a compromised admin workstation could serve as a pivot point for lateral movement within the organization (VulnCheck Advisory, Red Hat Advisory).
A public proof-of-concept exploit is available on Exploit-DB (EDB-51399), published alongside the CVE disclosure in December 2025 (Exploit-DB PoC). There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.061%, reflecting low but non-zero probability of exploitation in the near term. Exploitation requires an authenticated account and administrator interaction (triggering a CSV export), which limits opportunistic mass exploitation (VulnCheck Advisory).
=calc|a!z| or =cmd|' /C calc'!A0 (Windows) or a reverse shell variant.calc.exe or executing a reverse shell payload).=, +, -, @, tab \t, or carriage return \r) in the username/display name field.calc.exe, cmd.exe, powershell.exe, or bash) with a parent process of a spreadsheet application (Excel, LibreOffice).realname or display name columns (e.g., values starting with =, +, -, @).Organizations should update phpMyFAQ to a version beyond 3.1.12 that includes a patch for this vulnerability (VulnCheck Advisory). As an immediate workaround, implement strict server-side input validation on the user profile name field to reject or escape formula-injection characters (=, +, -, @, tab, carriage return). Administrators should be instructed to disable automatic macro and formula execution when opening CSV files from phpMyFAQ exports, or to open such files in a sandboxed environment. Additionally, restrict CSV export functionality to the minimum necessary administrators and audit user profile names for suspicious formula-like strings before performing exports (Red Hat Advisory).
The vulnerability was noted in CISA's weekly vulnerability bulletin for the week of December 15, 2025, indicating it received standard industry tracking attention (CISA Bulletin). No significant vendor statements beyond the VulnCheck advisory or notable researcher commentary beyond the Exploit-DB submission have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."