Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.
An attacker injects malicious formulas (e.g., starting with '=', '+', '-' or '@' characters) in fields such as 'Name', 'Gender' or 'Position' during user data import to the CrossChex system. The exported CSV file contains embedded formulas that are interpreted by the spreadsheet application (e.g., Microsoft Excel) as commands to execute. After the file is opened by a user with permissions to run macros, the payload is executed in the context of the spreadsheet application on the victim's computer.
An attacker can execute arbitrary system commands on the workstation of a user opening the infected CSV file, which may lead to system takeover, data theft, or installation of malicious software.
Apply patches available from the vendor according to the references. Additionally, it is recommended to disable automatic macro execution in spreadsheet applications (e.g., Microsoft Excel) and verify data imported from external sources before opening them.
Anviz AIM CrossChex Standard version 4.3.6.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X