CRITICAL🇵🇱 Wersja polska

CVE-2018-25135

CVSS 9.3v4.0pub. 2025-12-24upd. 2026-04-15

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

🤖 AI Analysis
How it works

An attacker injects malicious formulas (e.g., starting with '=', '+', '-' or '@' characters) in fields such as 'Name', 'Gender' or 'Position' during user data import to the CrossChex system. The exported CSV file contains embedded formulas that are interpreted by the spreadsheet application (e.g., Microsoft Excel) as commands to execute. After the file is opened by a user with permissions to run macros, the payload is executed in the context of the spreadsheet application on the victim's computer.

Impact

An attacker can execute arbitrary system commands on the workstation of a user opening the infected CSV file, which may lead to system takeover, data theft, or installation of malicious software.

Mitigation & patch

Apply patches available from the vendor according to the references. Additionally, it is recommended to disable automatic macro execution in spreadsheet applications (e.g., Microsoft Excel) and verify data imported from external sources before opening them.

Who is affected

Anviz AIM CrossChex Standard version 4.3.6.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References