HomeSecurityInjection in the 'Export to Spreadsheet' function

Injection in the 'Export to Spreadsheet' function

In this article we will explain the CSV injection technique, which exploits the “Export to Spreadsheet” function. While working on a project, this vulnerability was found in one of Microsoft’s products, CRM – Customer Relationship Management

 

What is CRM? :

It is a Microsoft product, used for the purpose of managing and analyzing customer interactions and data throughout the customer lifecycle, with the aim of improving business relationships with its customers.

Description:

Many web applications offer the ability to export spreadsheets, which allows an attacker to find fertile ground for their malicious code, so that when the victim downloads the csv file and opens it, the malicious code will be executed.

This is possible when a web application does not properly check the validity of input fields, so the attacker can insert some malicious code through the unvalidated input fields. As a result, the resulting spreadsheet cells contain malicious code. With the export feature, the user can download the file in .csv or .xls. This is inherently dangerous, because any cell that starts with “=” is interpreted as a formula by the spreadsheet.

[su_button url=”https://www.secnews.gr/103180/dual-boot-kali-linux-with-windows-10/” target=”blank” style=”glass” background=”#f26473″ color=”#1a211a7″ wide=”yes” center=”yes” radius=”20″ icon_color=”#ffffff”]Read also: How to dual boot Kali Linux & Windows 10!! Step-by-step[/su_button]

Successful exploitation would allow an attacker to execute arbitrary code with the privileges of the currently logged-in user on the system, causing severe damage to the victim's system, such as wiping out an entire partition or creating backdoors for later access. Many other attacks are possible, depending on the creativity of the attacker.

Exploitation Steps:

I. Login with valid user credentials and inject the malicious command (=cmd|' /C calc'!A0) into the user's “Full name” input field

CSV-INJECTION-step-1-1-768x410

II. Now create a lead and the owner will be the user's “Full name”

CSV-INJECTION-step-2-1-768x382

III. The Lead was successfully saved with the malicious code (=cmd|' /C calc'!A0) under the Owner field

CSV-INJECTION-step-3-1-768x434

IV. When the victim downloads the excel file, the malicious code will be successfully executed on the victim's system.
CSV-INJECTION-step-4-1-768x538

 

[alert size=”alert-block” variation=”alert-success”]SecNews.gr warmly thanks the friend of the website Fotis Tretas for the timely and accurate information[/alert]

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS